You can manage Rule Exceptions, Endpoint Exceptions, Allow Lists, and Block Lists all directly in the AgileBlue Portal.
Overview & Definitions
AgileBlue's SOC Analyst team and admin users in the portal can access a central location for managing Rule Exceptions, Endpoint Exceptions, Allow Lists, and Block Lists. This includes the ability to create, remove, and edit the related rules all within a single platform.
- Rule Exception
-
- A rule-level exclusion that prevents certain events or conditions from triggering alerts. We add rule exceptions to fine-tune Attack Indicators and rule out false positives.
-
- Endpoint Exception
-
- An Endpoint Exception prevents the Cerulean Agent from taking action and raising alerts for specific files, processes, or behaviors. These exceptions prevent legitimate applications or behaviors from being blocked or flagged by the EDR.
-
- Allow List
-
- A list of trusted entities (file hash/file path/file signature) that the agent will permit/ignore when evaluating threats. Items on the allow list are treated as safe and excluded from detections or preventative actions.
-
- Block List
-
- A list of known malicious, untrusted, or undesired entities that will be automatically blocked by the Cerulean Agent. Anything on the block list (file hash/file path/file signature) is denied execution.
- A block list entry might be created when a malicious executable is identified during an investigation. For instance, if a specific file hash is confirmed to belong to ransomware, it can be added to the block list to ensure the agent automatically prevents it from running across all monitored endpoints. This is also often used to prevent the installation/execution of common PUPs (potentially unwanted programs), or any software the client would prefer not to run in their environment.
-
Manage Rule Exceptions
Alert Exceptions can be applied to all Attack Indicators except for EDR/MDR alerts within the AgileBlue Platform. For exceptions related to EDR/MDR alerts, see the Endpoint Exceptions section of this document.
Create A Rule Exception
- There are two ways to add a Rule Exception listed below – we recommended following option a whenever possible:
- Navigate to the Alert for which you would like to add an exception
- Click Create Exception in the top right-hand corner
- Select Alert Exceptions on the left-hand menu in the AgileBlue Portal then click Rule Exceptions
- Select the specific rule for which you would like to add an exception then click Add Exception
- NOTE: If you are logged in to a multi-tenant portal, ensure the target tenant is selected from the dropdown menu.
- Navigate to the Alert for which you would like to add an exception
- Give a name for your new Exception
- Enter the Field the exception should be applied to (Ex. process.name)
- NOTE: When entering the field, it must exactly match the alert type. The exceptions will not work correctly unless the field type is a match.
- Select one of the available operators
- is
- is not
- is one of
- is not one of
- Enter the Value for the exception (Ex. svchost.exe)
- NOTE: The exception will not function properly unless the Value is an exact match.
- Click +Add Conditional to include additional fields and values or click Save to create your exception
Edit Existing Rule Exception
- Click on the target Attack Indicator
- Select the Pen Icon
- Update the exception
- Click Save
Delete Existing Rule Exception
- Click on the target Attack Indicator
- Select the Trashcan Icon next to the exception to be removed
Manage Endpoint Exceptions
Endpoint Exceptions are specific to EDR/MDR alerts.
Create An Endpoint Exception
- There are two ways to add an Endpoint Exception listed below – we recommended following option a whenever possible:
- Navigate to the EDR/MDR Alert for which you would like to add an exception
- Click Create Exception in the top right-hand corner
- Select Alert Exceptions on the left-hand menu in the AgileBlue Portal then click Endpoint Exceptions
- Select the specific rule for which you would like to add an exception then click Add Exception
- NOTE: If you are logged in to a multi-tenant portal, ensure the target tenant is selected from the dropdown menu.
- Navigate to the EDR/MDR Alert for which you would like to add an exception
- Give a name for your new Exception
- Add a Client Identifier
- For all Endpoint Exceptions, a specific Client Identifier must be included; set the Field to one of the following values:
- Custom.client_id
- client_id
- host.domain
- user.domain
- NOTE: Some alerts may not work unless the correct Client Identifier is entered. If the exception does not work with Custom.client_id, move on to the next option on this list until the exception is successfully configured.
If you are manually adding an exception (not tied to a specific alert), the client ID can be found on the tenant's alert playbook page. Host domain and user domain values can be found in the corresponding alert logs.
- Set the Operator to is
- If the Value does not auto populate, fill in that field
- For all Endpoint Exceptions, a specific Client Identifier must be included; set the Field to one of the following values:
- Click +Add Conditional
- Enter the details regarding the activity to be excepted – to learn more about how to create effective endpoint exceptions, click here
Edit Existing Endpoint Exception
- Click on the target Exception
- Select the Pen Icon
- Update the exception
- Click Save
Delete Existing Endpoint Exception
- Click on the target Exception
- Select the Trashcan Icon next to the exception to be removed
Manage Allow List & Block List
Allowlist and Block List only apply to tenants with EDR fully enabled through the AgileBlue Platform. If EDR is disabled or in passive mode, the blocklist will not function. These sections can be used to specifically allow or block applications based on a file path, hash, or signature. The Allow List should only be used for critical trusted applications the require 99.9% uptime.
Block List should be used for any known and potentially unwanted program to be blocked across the entire organization.
Update Allow List
- Log in to the AgileBlue Portal and navigate to Alert Exceptions in the left-hand menu
- NOTE: If you are logged in to a multi-tenant portal, ensure the target tenant is selected from the dropdown menu.
- Select the Allow List tab
- Click + Add Allow List Item
- Enter a Item Name
- Select one or more policies the item should be applied to (in almost all instances, any available policy should be included)
- Select the target OS Types
- Select the Field to be allowed (Hash, Path, or Signature)
- Enter the Value
- Click + Add Conditional to add another parameter to the item or click Save
Update Block List
- Log in to the AgileBlue Portal and navigate to Alert Exceptions in the left-hand menu
- NOTE: If you are logged in to a multi-tenant portal, ensure the target tenant is selected from the dropdown menu.
- Select the Block List tab
- Click + Add Block List Item
- Enter a Item Name
- Select one or more policies the item should be applied to (in almost all instances, any available policy should be included)
- Select the target OS Types
- Select the Field to be allowed (Hash, Path, or Signature)
- Enter the Value
- Click + Add Conditional to add another parameter to the item or click Save
Edit Existing Allow List/Block List Item
- Click on the target Item
- Select the Pen Icon
- Update the item
- Click Save
Delete Existing Allow List/Block List Item
- Click on the target Item
- Select the Trashcan Icon next to the exception to be removed
Questions? Contact AgileBlue Support.
Email: support@agileblue.com
Phone: (216) 606-9400