Skip to main content
Question

Tune File ThreatIndicators

  • September 5, 2025
  • 2 replies
  • 24 views

Forum|alt.badge.img+8

How can we finetune the the file activity of the the threat indicators on individual servers.

We have some servers in our environment that triggers on specific occasions, as false positives.

One instance is SCCM servers, which triggers when updates are modified and prepared.

Another is a large fileserver that has some batchjob running at intervals modifying large amount of files.

 

Could turn them off, but would like to check if I’m able to finetune this to get less false positives.

 

I see there is additional settings to exclude paths, Enable I/O detection patterns and training dataset size.

The two last ones I cannot find any clear documentation on what they do. Maybe someone has some more information?

2 replies

CV_GK
Vaulter
Forum|alt.badge.img+7
  • Vaulter
  • September 8, 2025

Hi ​@John Robert 

What is the CV version here?


Forum|alt.badge.img+8
  • Author
  • Byte
  • September 8, 2025

@CV_GK Currently 11.36, but soon to be upgraded to 11.40