General Configuration
Copy link

The following topics apply to all integrations.

Stop an integration from sending IOCs
Copy link

You can stop an integration from pushing IOCs to the device by deleting the IOC group.

To stop an integration:

  1. From the Command Platform, go to Data Connectors > Threat Intelligence > Integrations.
  2. Click the Cloud tab.
  3. From the Integrations device list, click a device name.
  4. Point to the group then click the delete icon.

The group is deleted, and no further IOCs will be sent.

View current IOC management rules
Copy link

  1. From the Command Platform, go to Automation > Digital Risk Protection > DRP Policy.
  2. Under IOC Management, click IOC

Rules that have already been defined are displayed in the IOC rules list.