Add Threat Intelligence Director observables to a Do Not Block list

Adding observables to a Do Not Block list allows you to exempt specific items from being blocked, ensuring legitimate traffic is not inadvertently restricted.

For detailed information about using Do Not Block lists, refer to Adding Threat Intelligence Director observables to the Do Not Block list.

Tip

An "Add to Do Not Block List" button (The "Add to Do Not Block List" button is highlighted in the web interface, indicating where users can exempt specific observables from being blocked.) can appear in several places in the web interface. You can add an observable to a Do Not Block list in any of those locations by clicking this button.

Procedure


Step 1

Choose Integrations > + Show more > Threat intelligence director > Sources, and click Observables.

Step 2

Navigate to the observable that you want to allow.

Step 3

Click The observable is successfully added to the Do Not Block list, indicating it will be exempt from any blocking actions. (Add to Do-Not-Block List) for that observable.


What to do next

(Optional) If you need to remove an observable from the Do Not Block list, click the button again.