cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
180
Views
0
Helpful
1
Replies

MARS - False Positives

pavlosd
Level 2
Level 2

Hi All,

Any ideas how I could delete some user-defined false possitives I created under incidents/false possitives/"User Confirmed False Possitives"?

1 Reply 1

pmccubbin
Level 5
Level 5

This is an excellent question. It is one that has been asked of me by my clients and I heard it asked in the MARS class I attended. The answer I was given:

In order to keep your database from becoming corrupted, rules you create cannot be deleted. They can only be deactivated.

Think about the fact you are profiling a network by using a MARS box. If you can later go in and delete entries in this profile the information is no longer completely valid. Every subsequent deletion further denigrates the profile that has been created. The creators of the MARS box realized this and prohibited anybody from altering the data. They did this so your efforts to mitigate a problem would be as accurate as possible.

If you create a lot of rules and the number of false positves in your database is excessive, all you can do is wipe the box clean and start over. Hopefully you have created a seed file for your devices so you don't have to re-enter them one at a time.

Hope this answers your question.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: