Alert Whitelisting and Event Retention

The EDR solution provides flexible Alert Whitelisting and Event Retention capabilities that enable Incident Responders (IR) and authorized security analysts to manage trusted activities while maintaining sufficient historical endpoint telemetry for investigation and compliance requirements.

1. Alert Whitelisting

The EDR solution allows an Incident Responder to whitelist alerts generated by trusted or verified activities.

Whitelisting can be configured using individual parameters or a combination of multiple parameters, providing granular control over which activities are considered trusted.

Supported whitelisting parameters include:

  • Process
  • Command Line
  • Process Path
  • Network IP Address
  • Network Protocol

For example, an analyst can create a rule based on:

Process = "putty.exe"

or create a more specific rule using multiple conditions:

Process = "putty.exe" AND Process Path = "C:\Tools\putty.exe" AND Network IP = "11.22.33.44" AND Protocol = "TCP"

This combination-based approach allows analysts to create precise whitelisting rules while minimizing the possibility of broadly excluding legitimate security detections.

2. Combination-Based Whitelisting Rules

The solution allows Incident Responders to select multiple parameters together when creating a whitelisting rule.

This provides greater control compared with whitelisting based on a single attribute.

For example, instead of allowing every instance of a process, an analyst can restrict the rule to a specific:

Process + Command Line + Path + IP + Protocol

This helps maintain security while allowing known and trusted business activities.

3. Modification of Whitelisting Rules

Authorized administrators and Incident Responders can modify existing whitelisting rules when requirements change.

Existing parameters can be reviewed and updated to reflect changes in:

  • Process
  • Command Line
  • Process Path
  • Network IP
  • Network Protocol
  • Other supported rule conditions

This provides flexibility without requiring a new rule to be created from scratch.

4. Deletion of Whitelisting Rules

The EDR solution provides an option to delete existing whitelisting rules.

When a previously trusted application, process, network connection, or activity is no longer required to be excluded, the corresponding whitelisting rule can be removed.

Once removed, applicable activities are again evaluated according to the active EDR detection and security policies.

5. Centralized Whitelisting Management

Whitelisting rules are managed through the centralized EDR Management Console.

Authorized personnel can create, review, modify, and delete rules from a central interface, providing consistent control over trusted activities across protected endpoints.

This also helps security teams maintain visibility into the exceptions applied within the environment.

6. Event Retention

The EDR solution retains endpoint events generated across the network for a minimum period of 30 days.

The retained event information provides historical visibility into endpoint activities and supports:

  • Incident investigation
  • Threat hunting
  • Alert analysis
  • Root-cause investigation
  • Historical activity review
  • Security auditing
  • Incident response

Analysts can use retained telemetry to investigate events that occurred previously and correlate historical activities with current security incidents.

7. Investigation and Security Benefits

The combination of granular whitelisting and event retention provides a balanced approach between security enforcement and operational flexibility.

Analysts can safely allow verified legitimate activities using precise whitelisting conditions while maintaining historical endpoint telemetry for investigation.

The overall workflow provides:

Detect → Investigate → Verify → Whitelist Trusted Activity → Monitor → Modify/Delete Rule When Required → Retain Historical Events

This enables security teams to manage trusted activities efficiently without compromising visibility into endpoint events.