Threat Rule Templates for Service Providers (Beta)

Applies To: WatchGuard CloudDR

Threat rule templates in WatchGuard CloudDR are available as a beta feature.

On the Threats > Templates page, Service Providers can centrally manage and apply threat rule templates to their Subscriber accounts. Templates use a tag-based assignment model. When a rule tag matches an organization tag, CloudDR deploys that rule template to the organization.

Screenshot of Threat > Templates page in CloudDR

Create a Rule Template

Before you add tags to a rule on the Templates page, you should add tags to your organizations. Tags act as logical groups that help you organize organizations and determine which rule templates apply to them. For information on how to add a tag to an organization, go to About Organizations in WatchGuard CloudDR.

To create a rule template:

  1. Select Threats > Templates.
  2. From the list, select a built-in rule that you want to apply tags to.
    The Rule details page opens.
  3. Next to Applied Tags, click Edit icon..

Screenshot of threat rule details page in CloudDR

  1. Below the Tags text box, select the tags you want to apply. You can select more than one tag. You can also enter a new tag in the text box. If you enter a new tag, make sure to assign the new tag to organizations.

Screenshot of Edit Tags dialog box in CloudDR

  1. Click Save.
  2. On the Rules details page, make additional changes to the rule, if required. Click Update Rule.
    If you cannot edit the details, create a duplicate of the rule and customize it.
  3. On the Templates page, click Apply Templates.

Changes to rules and tag assignments are automatically saved as you make them. Updates are not deployed to organizations until you click Apply Templates.

Duplicate a Rule

If you cannot edit the details of a rule you want to use as a template (for example, the rule pass criteria), then you can duplicate the rule and make changes.

To duplicate a rule:

  1. Select the rule you want to duplicate.
  2. On the Rules details page, click Duplicate Rule.
  3. In the Rule Name text box, type a new name for the rule.
  4. Click Create New Rule.
    The new rule shows in the templates list.
  5. From the templates list, select the new rule.
    Custom icon. shows in the row for custom rule templates.

Screenshot of threat rule duplicate template in CloudDR

  1. To edit the details and rule pass criteria, click Edit icon..
    For information on how to edit the rule pass criteria in a threat rule, go to Edit Rule Pass Criteria in WatchGuard CloudDR.
  2. Add tags to the rule.
  3. Click Update Rule.
  4. On the Templates page, click Apply Templates.
    CloudDR deploys the rule template to the tagged organizations.

Manage Templates

The templates list includes all available system rules, including this information:

  • Rule Name — The name of the threat rule and the related security domain. Point to the rule name for a detailed description.
  • Tags — Text descriptors applied to the rule and organizations. A rule can have multiple tags. Tags enable CloudDR to apply a rule to an organization with the same tag.
  • Applications — The application where the threat was detected.
  • Last Modified — The date when the last activity on the threat (opened or resolved) occurred.
  • Severity — The severity level of the threat rule.
  • Status — Enable or disable a single rule template. To enable or disable multiple rules, select the check boxes next to the rules, then click Enable Rules or Disable Rules.

To search for a specific rule, enter the rule name in the Search Rule Name text box.

You can filter the list by:

  • Tags
  • Severity
  • Risk
  • Status
  • Application
  • Custom Rules

Change Rule Severity

You can change the severity for an existing rule or create a new rule.

To change the rule severity:

  1. Click in the row.
  2. Select Change Severity.
  3. From the drop-down list, select a new severity level.
  4. Click Update Rule.
  5. To create a new rule, click Create New Rule.

Enable and Disable Rules on the Templates Page

To enable or disable multiple rules in the list:

  1. On the Templates page, select the rules you want to update.
  2. Click Enable Rules or Disable Rules.
  3. Confirm that you want to enable or disable the rules.

Rule Details Page

To view more detailed information about a rule template, select a rule from the list. The rule details page opens.

Screenshot of threat rule template details, CloudDR

If you cannot edit details of the rule (for example, the rule pass criteria), then you can duplicate the rule and make changes. For more information, go to Duplicate a Rule.

The rule details page includes information on these tabs:

Click a tab to view additional information for the rule.

Details

On the Details page, review a description of the threat rule or policy, the tags applied, the number of open issues, severity, and risk. You can edit the Severity and Applications in the rule. You can also view and edit the tags applied to the rule template.

In the Rule Pass Criteria section, you cannot edit the values. To make changes, you can create a duplicate of the rule, or edit the rule directly on the Rules page.

For information on how to duplicate a rule, go to Duplicate a Rule.

For information on how to edit the rule pass criteria in a threat rule, go to Edit Rule Pass Criteria in WatchGuard CloudDR.

Remediations

On the Remediations page, you can view the general instructions to resolve or remediate threats.

Automation

On the Automation page, you can set up a quick action to run when a new threat is detected for the rule. For more information, go to Add Autofix Automation for Threats in WatchGuard CloudDR.

Template rules support tag-specific automations.This enables different organizations to initiate different response actions while they share the same overall rule framework. For example:

  • Organizations with the New tag could send an email notification when a rule triggers.
  • Organizations with the Default tag could automatically remediate the same threat.

MITRE ATT&CK

On the MITRE page, review the MITRE techniques and sub-techniques associated with the threat.

Related Topics

Automated Threat Response Actions in WatchGuard CloudDR

Edit Rule Pass Criteria in WatchGuard CloudDR

Add Autofix Automation for Threats in WatchGuard CloudDR