Excluding Pentera Box

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Excluding Pentera Box

L0 Member

I am looking to make an exclusion or suppression of some sort for alerts generated by our Pentera Security Validation Tool. I have a SSL certificate loaded into Pentera so I can filter by that certificate if I can. However for the Vulnerability Scans with Pentera I cant use the SSL cert or any other identifier. Just trying to keep down the noise in Cortex.

1 REPLY 1

L0 Member

With Cortex XDR Pro you can automate the Alerts via Rules (AutomationRules). I do this with an automation that auto-closes (with subject "pentest") all the alert when I detect the CGO is from the Pentera MainNode IP (or the RANs, if any). IMHO this is much easier than the possibilities you have with signing the payload and or using pre/post-fixes within pentera.
With this the alerts/incidents from the pentest are staying visible in the Cortex backend (they are not excluded, just closed...) but do not fill your active incidents/alerts table.
BTW: this perfectly works also well for Detects out from a Vulnerability Assessment only - port scans for instance...

  • 241 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!