Kaspersky Anti Targeted Attack Platform

Managing user-defined rules

For additional protection of the corporate IT infrastructure, you can configure TAA, IDS, IOC, and YARA custom rules.

Users with the Senior security officer role can work with custom TAA, IDS, IOC, and YARA rules: load and delete rule files, view lists of rules, and edit the selected rules.

Users with the Security auditor role can view the lists of custom TAA, IDS, IOC, and YARA rules and properties of selected rules without the possibility of editing.

Users with the Security officer role can view the lists of custom TAA, IOC, and YARA rules and properties of selected rules without the possibility of editing.

In this section

Using indicators of compromise (IOC) and attack (IOA) for Threat Hunting

Managing user-defined TAA (IOA) rules

Managing user-defined IOC rules

Managing user-defined Intrusion Detection rules

Managing user-defined YARA rules