Kaspersky Endpoint Detection and Response Expert
Creating exclusions from Kaspersky IOA rules
Creating exclusions from Kaspersky IOA rules
You can create exclusions from rules made by Kaspersky from alert details and event details. If you do not want to use a created exclusion for scanning events, you can delete it.
To create an exclusion from alert details:
- Do one of the following:
- In the main menu, go to MONITORING & REPORTING → Alerts, and then open the details of the alert that is triggered by the Kaspersky IOA rule.
- In the main menu, go to MONITORING & REPORTING → Threat hunting, and then open the details of the event that is triggered by the Kaspersky IOA rule.
- Make the necessary changes in the following fields:
- Click the Save button.
The exclusion is created. You can view and manage exclusions in the Custom rules section.
Article ID: 226703, Last review: Mar 26, 2025