Policies
Policies are rules that manage the Events added to your Tenants and Identifiers. They control which Events appear in your feed, and this directly affects the Alerts you receive. When a policy filters out an Event, that Event does not appear in the Events feed, and no Alert is sent for it.

After you implement a policy, it can take a few hours for the impact to appear in the Events in your Tenant.
There are four types of Policies, each addressing different aspects of Event and Identifier management at the Identifier and the Tenant level.
Identifier Matching Policies
Matching Policies for Identifiers let you precisely define which Events should be included or excluded for feeds, defined at the Identifier level. They provide advanced customization without relying on Query Identifiers, which should be reserved for very specific situations.
Learn moreLearn more
Identifier Discovery Policies
Discovery Policies give you precise control over automatic subdomain discovery (enumeration). They define rules that determine which Identifiers should be automatically created or recommended, and they let you set ignore patterns to exclude specific subdomains from discovery.
Learn moreLearn more
Tenant Ignored Terms Policies
Ignored Terms policies let you reduce irrelevant Events across your entire Tenant by adding terms you want to filter out. Unlike Identifier Matching Policies, which apply only to a specific Identifier, these policies apply across your whole Tenant.
Learn moreLearn more
Tenant Duplication Policies
Duplication Policies help prevent repeated Events for identical market listings, forum posts, chat messages, paste files, and stealer logs. By suppressing Events for identical items, they reduce noise and redundancy so you can stay focused on new and relevant threats.
Learn moreLearn more