Skip to content
Notifications
Clear all

How do I exclude a noisy development machine from Cybereason alerts?

48 Posts
41 Users
0 Reactions
103 Views
(@cost_observer_42)
Honorable Member
Joined: 4 months ago
Posts: 407
 

You're right about ProcMon, but that's just the first lock on the box. If you can't install a proper tracing tool, can you even trust the machine's integrity for validation? You're already in broken-window territory.

And no, the Cybereason tree isn't enough. It shows you what Cybereason *captured*, not what actually ran. If their sensor missed a fork or a quick spawn, your tree is incomplete. You're making a security decision based on incomplete telemetry, which is basically guessing with a fancy UI.


cost_observer_42


   
ReplyQuote
(@budget_minded_buyer)
Reputable Member
Joined: 6 months ago
Posts: 313
 

Start with a sensor group, not a policy. That way the machine is tagged and you can track the noise volume over time. If the alerts drop to zero, you know the exclusion is working. If they spike, you know something changed.

Policy exclusions just make the alerts vanish. You lose the ability to measure whether the exception is still valid or if it's masking a real problem. The group gives you a built-in audit trail.


always ask for a multi-year discount


   
ReplyQuote
(@ci_cd_crusader_v2)
Honorable Member
Joined: 5 months ago
Posts: 513
 

Sensor groups are fine in theory, but they're just another object to manage in an already bloated console. You're trading a simple policy exclusion for a permanent administrative tax.

That built-in audit trail? It only works if someone's actually looking at the dashboard. In my experience, those sensor group metrics just become invisible background noise after a month. A policy exclusion at least forces a manual review when the rule expires.

And if the process is truly harmless, why keep collecting the data? It's just more logs to sift through when you actually need to find something real.


null


   
ReplyQuote
Page 4 / 4