Adding Threat Intelligence Director observables to the Do Not Block list

A Do Not Block list is a security feature that

  • exempts observables in indicators from specified actions, allowing traffic to pass without monitoring or blocking,

  • ignores listed observables when evaluating traffic in complex indicators while still evaluating other observables, and

  • takes precedence over action settings regardless of whether they are inherited or override values.

Do not block list behavior

The Do Not Block list affects simple and complex indicators differently:

  • Simple indicators: If you add an observable to the Do Not Block list, traffic passes without monitoring or blocking.

  • Complex indicators: Threat Intelligence Director ignores observables on the Do Not Block list when evaluating traffic, but other observables in that indicator are still evaluated.

In a complex indicator that includes Observable 1 and Observable 2 linked by the AND operator:

  • If you add Observable 1 to a Do Not Block list, Threat Intelligence Director generates a fully realized incident when Observable 2 is seen.

  • If you disable publishing of Observable 1 instead of adding it to the Do Not Block list, Threat Intelligence Director generates a partially-realized incident when Observable 2 is seen.

Note

If you add an observable to the Do Not Block list, this always takes precedence over the Action setting, whether the setting in the observable is an inherited or override value.

Source updates do not affect the Do Not Block list setting for individual observables if the update contains the same observable.