Threat Rule Templates for Service Providers (Beta)
Applies To: WatchGuard CloudDR
Threat rule templates in WatchGuard CloudDR are available as a beta feature.
On the Threats > Templates page, Service Providers can centrally manage and apply rules to their Subscriber accounts. A template is a rule with one or more tags that you can apply to an organization with the same tag.
For information on how to add a tag to an organization, go to About Organizations in WatchGuard CloudDR.
To enable or disable multiple rules:
- On the Templates page, select the check boxes for the rules you want to update.
- Click Enable Rules or Disable Rules.
- Confirm that you want to enable or disable the rules.
You can filter the rules list by:
- Tags
- Severity
- Risk
- Status
- Application
- Custom Rules
To search for a specific rule, enter the rule name in the Search Rule Name text box.
Information in the list includes:
- Rule Name — The name of the threat rule and the related security domain. Point to the rule name for a detailed description.
- Tags — Text descriptors applied to the rule and organizations. A rule can have multiple tags. Tags enable CloudDR to apply a rule to an organization with the same tag.
- Applications — The application where the threat was detected.
- Last Modified — The date when the last activity on the threat (opened or resolved) occurred.
- Severity — The severity level of the threat rule.
- Status — The enabled or disabled state of the rule template.
Template Details Page
To view more detailed information about a rule template, select a rule in the list.
The template details page includes these tabs:
On the Details page, review a description of the threat rule or policy, the tags applied, the number of open issues, severity, and risk. You can edit the Severity and Applications in the rule. You can also view and edit the tags applied to the rule template.
To edit the tags, click
next to Applied Tags. Select an existing tag or in the Tags text box, enter a new tag.
In the Rule Pass Criteria section, you cannot edit the values. To make changes, you can create a duplicate of the rule, or edit the rule directly on the Rules page.
For information on how to duplicate a rule, go to Duplicate a Rule.
For information on how to edit the rule pass criteria in an issue rule, go to Edit Rule Pass Criteria in WatchGuard CloudDR.
On the Remediations page, you can view the general instructions to resolve or remediate threats.
On the Automation page, you can set up a quick action to run when a new threat is detected for the rule. For more information, go to Add Autofix Automation for Threats in WatchGuard CloudDR.
On the MITRE page, review the MITRE techniques and sub-techniques associated with the threat.
Duplicate a Rule
You cannot edit the rule pass criteria of a rule template. To make changes, create a duplicate of the rule.
To create a duplicate of the rule:
- On the Template Details page, click Duplicate Rule.
- In the Rule Name text box, type a new name for the rule template.
- Click Create New Rule.
The new rule shows in the templates list. - From the templates list, select the new rule.
The
icon shows for custom rule templates. - To edit the details and rule pass criteria as required for the template, click
. - Add tags for the template.
- On the Templates page, click Apply Changes.