Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
paki
Participant

Best Practice for Threat Prevention and discuss about False Positive Handling

Hello everyone, 

I would like to ask for best practice regarding your experience in Threat Prevention choice.

What do you recommend in production environments:
Autonomous Threat Prevention or Custom Threat Prevention?

One more thing, I'm particularly interested in reducing false positives and understanding how other administrators handle detection tuning.

Also, what is the best way to identify and analyze false positive events in Threat Prevention logs?
Do you usually rely on SmartConsole logs or some other methods?

I would appreciate recommendations based on real production experience.

Thanks in advance!

0 Kudos
0 Replies

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events