Adding Threat Intelligence Director observables to the Do Not Block list
A Do Not Block list is a security feature that
-
exempts observables in indicators from specified actions, allowing traffic to pass without monitoring or blocking,
-
ignores listed observables when evaluating traffic in complex indicators while still evaluating other observables, and
-
takes precedence over action settings regardless of whether they are inherited or override values.
Do not block list behavior
The Do Not Block list affects simple and complex indicators differently:
Simple indicators: If you add an observable to the Do Not Block list, traffic passes without monitoring or blocking.
Complex indicators: Threat Intelligence Director ignores observables on the Do Not Block list when evaluating traffic, but other observables in that indicator are still evaluated.
In a complex indicator that includes Observable 1 and Observable 2 linked by the AND operator:
If you add Observable 1 to a Do Not Block list, Threat Intelligence Director generates a fully realized incident when Observable 2 is seen.
If you disable publishing of Observable 1 instead of adding it to the Do Not Block list, Threat Intelligence Director generates a partially-realized incident when Observable 2 is seen.
Note | If you add an observable to the Do Not Block list, this always takes precedence over the Action setting, whether the setting in the observable is an inherited or override value. |
Source updates do not affect the Do Not Block list setting for individual observables if the update contains the same observable.