Views:

To mitigate those unnecessary detections, do the following:

  1. Check that Deep Discovery Inspector is configured correctly. Refer to linked articles under Recommended DDI Configurations in Deep Discovery Inspector (DDI) 5.7 Best Practice Guides.
  2. Check the detection details through Detections > All Detections, then identify triggered rules and objects.
  3. In order to mitigate aggressive or false positive detection on Deep Discovery Inspector, update any or all of the following configurations depending on the situation:
    1. To ignore detections by a specific detection rule, go to Administration > Monitoring/Scanning > Detection Rules, and disable a detection rule which is considered unnecessary.

      allow connection

    2. To ignore a detection which meets a particular criteria, such as Host name, Protocol, or File SHA-1 etc, go to Administration > Monitoring/Scanning > Detection Exceptions, and then register an appropriate criteria into the Detection Exception list.

      ignore detection

    3. To allow the connection to particular entities, go to Administration > Monitoring/Scanning > Deny List/Allow List, and then register File SHA-1, IP address, URL or domain into Allow List.

      ignore detection