Triage, Review, and Whitelist Results

Learn about RocketCyber's powerful result review and triage tools

Review

Review and whitelisting can be performed at the MSP, Customer or Device Level

Each RocketApp provides an app result or detection whenever a suspicious or malicious event is detected. These app results are aggregated per RocketApp and the counts are displayed on the dashboard as shown below.

Click Review to begin reviewing the app results for the desired app.

dashboard-shot-png.png

 

This is the main triage interface.
You can click on Details next to any result to get more details about the detected item.
Quickly switch between apps using the Switch App dropdown in the top right.
screen-shot-2020-01-27-at-9-13-27-pm.png

The detail dialog displays important detail information about the detection.

You can quickly cycle through the details using the left or right arrow keys or by clicking the arrow in the bottom left or right of the screen.

screen-shot-2020-01-27-at-9-22-46-pm.png

 

Search for specific detections using the Search feature or the date filters.

If you want to view results only for a specific device, click on the device name in the grid. This will change the view to only the results related to that device as shown below.

 

screen-shot-2020-01-27-at-9-13-27-pm.png

Whitelisting

Most apps support the concept of whitelisting. This allows you to tune the detection results and ignore acceptable risks or known behavior.

 1.    Select the items from the review list then click the Action button.

screen-shot-2020-01-27-at-9-25-00-pm.png

 2.    After selecting whitelist rules, click Add.  Select Remove Existing Results to delete existing results that match your new whitelist rule.

 

screen-shot-2020-01-27-at-9-34-21-pm.png

Once the items are added to the whitelist they should not be reported in the console from that point forward.

Best Practice

It is best practice to perform triage and review on a daily basis, whitelisting as necessary to get to a steady-state. When app results are no longer needed it is best to delete them using the review interface.

Was this article helpful?
0 out of 0 found this helpful
Have more questions? Contact us