On the Detection Rules subtab of Real-Time Coaching, you can create and manage your detection rules. Detection rules identify which user behaviors you want to track using data from your integrated vendors. For example, you may want to detect when your users visit prohibited websites, download malicious attachments, or click phishing links. If a user triggers a detection rule, that event will display on the user’s timeline.
We offer system detection rules based on the default policies of integrated vendors. These rules are enabled by default and require no further configuration. You can also create custom detection rules for your custom vendor policies.
For general information about Real-Time Coaching, see our Real-Time Coaching Overview.
Creating a Custom Detection Rule
To use custom detection rules in Real-Time Coaching, first set up a corresponding custom policy in a security vendor’s platform. To work properly, custom detection rules must match the security vendor's custom policies. To configure a custom security vendor policy, please refer to your vendor’s product documentation or contact their support team.
Once you have configured a custom security vendor policy, you can create a matching custom detection rule by following these steps:
- Log in to your KnowBe4 console’s Security Awareness Training (SAT).
- Navigate to the Coaching tab > Detection Rules subtab.
- Select + Create Detection Rule at the top-right corner of the page.
-
Fill out the fields on the Create New Detection Rule page. For more information about these fields, see the screenshots and lists below:
- Name: Enter a name for your detection rule.
-
Vendor: Select a vendor for your detection rule.
Note:You must integrate vendors with SecurityCoach before they can be displayed in this drop-down menu. The KnowBe4 SAT vendor is integrated by default. To add additional vendors, integrate them with SecurityCoach. For more information about integrating vendors, see our Setting Up Integrations section. - Category: Select a category for your detection rule.
- Risk Level: Select a risk level for your detection rule.
- Description: Enter a description of your detection rule. For example, you could describe the purpose of the rule or include information that other admins may need to know about the rule.
- Detection Rule Criteria: Create a criterion for your detection rule using the three drop-down options. Then, select Save Criterion to add the criterion to your detection rule. Repeat this process to add additional criteria for your detection rule. For more information about the operators that you can use for the criterion, see the Detection Rule Operators section below.
-
Detection Rule Threshold: Customize how often this detection rule should trigger, using one of these two options:
- Trigger this rule any time a user has a qualifying event: Trigger this rule any time an event meets the set criteria.
- Trigger this rule when a user meets the minimum count of X qualifying events within Y days: Trigger this detection rule only when the criteria have been met a set number of times over a set number of days. For example, you can use this setting to trigger the detection rule for any users that have three qualifying events within 30 days.
- Select Save to save your changes and create the rule.
Detection Rule Operators
The following operators are available when creating a detection rule criterion.
| Operator | Description |
|---|---|
| Is | This operator checks if the field and value match. You can enter only one value when using this operator. |
| Is Not | This operator checks if the field and value do not match. You can enter only one value when using this operator. |
| Contains | This operator checks if the field contains the value. You can enter only one value when using this operator. |
| Does Not Contain | This operator checks if the field does not contain the value. You can enter only one value when using this operator. |
| Starts With | This operator checks if the field starts with the value. You can enter only one value when using this operator. |
| Ends With | This operator checks if the field ends with the value. You can enter only one value when using this operator. |
| Starts with Any Of | This operator checks if the field starts with any of the values. |
| Ends with Any Of | This operator checks if the field ends with any of the values. |
| Contains Any Of | This operator checks if the field contains any of the values. |
| Contains None Of | This operator checks if the field contains none of the values. |
| Is Any Of | This operator checks if the field matches any of the values. |
| Is None Of | This operator checks if the field does not match any of the values. |
Managing and Editing Detection Rules
To manage and edit your detection rules, navigate to the Coaching tab > Detection Rules subtab.
To learn more about the options on the Detection Rules subtab, see the screenshot and list below:
- Status: Filter detection rules by status by selecting All, Active, Inactive, or Maintenance.
- Type: Filter detection rules by type by selecting All, Custom, or System.
- Vendors: Filter detection rules by vendor.
- Category: Filter detection rules by category.
- Search: Enter keywords in this field to search for a specific detection rule.
- Toggle: Enable or disable a detection rule.
- Eye icon: View the system detection rule. When you click this icon, you will be taken to the View Detection Rule page, where you can view the details for the system detection rule.
-
Three dots icon: Open a drop-down menu with the following options:
-
Edit: Open the Edit Detection Rule page. On this page, you can edit a custom detection rule as needed. Grayed-out options can’t be changed. Select the Save button at the bottom-left corner of the page to save your changes.
Note:If the detection rule was cloned from a system detection rule, you can also select the Restore Default Settings button to return the rule to its default settings. - Clone: Clone a system detection rule. When you select this icon, you will be taken to the Clone Detection Rule page. On this page, you can modify the rule and save it as a custom rule.
- Delete: Delete a custom detection rule. System detection rules can’t be deleted, only disabled.
-
- + Create Detection Rule: Select this button to create a new detection rule.
Example Detection Rule
See the screenshot below for an example of a detection rule:
In this example, the following Detection Rule Criteria were added to the detection rule:
- Threat Category is bulk forwarding by user.
- Threat Category is Suspicious email forwarding activity.
This detection rule will be triggered when either criterion is met. Using this configuration, a user would need to either have suspicious email forwarding activity or be forwarding emails in bulk to trigger this rule.
Further down, we then select a SecurityTip related to the targeted email activity. Finally, we’ll enable all User Feedback options to better understand how coaching is working for our users.



