02-27-2017 08:51 AM - edited 03-10-2019 06:47 AM
FireSight has a list of signatures that it recommends for disabling. What are the requirements that these signatures meet to be recommended for disabling?
Solved! Go to Solution.
02-27-2017 11:56 PM
It really depends on the rule.
The recommendation is made having these things in mind; Network Analysis Policy, Host Profiles, "Rule overhead", CVSS score, etc..
If the rule does not have a CVSS score the recommendation is always to disable the rule. Try searching for "blacklist" in the rules. This is not my recommendation.
02-27-2017 11:56 PM
It really depends on the rule.
The recommendation is made having these things in mind; Network Analysis Policy, Host Profiles, "Rule overhead", CVSS score, etc..
If the rule does not have a CVSS score the recommendation is always to disable the rule. Try searching for "blacklist" in the rules. This is not my recommendation.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide