#
Follow these steps to configure a Threat Rule:
| Navigate to __Configuration | Identify | Threat Rules__. |
For Framework Control, enter the control name, for example, for NIST CSF v2.O, it could be PR.AA-03.
[!note] Multiple framework references can be added for a given risk factor.
You may also edit an existing custom Threat Rule via the edit button. Default Threat Rules can’t be edited.
Use the Rule Matches button to retrieve all accounts that match the specific rule. Rule matching is not available for aggregation rules.
Refer to the Integrate section to learn about actions based on threat rules.
[!Note] To activate the workflow and threat rule association, enable the Allow Workflow Trigger checkbox on the add/edit Threat Detection Rule modal.
