Skip to main content

Command Overview

beacon rules remove removes one installed threat-detection rule from the local store by rule id.
Command syntax
beacon rules remove <id> [flags]
Use beacon rules list first when you need to confirm the active rule ids.

Examples

Remove one rule from the user-mode store:
Remove a rule
beacon rules remove suspicious-egress-command
Remove one rule from the system-mode store:
Remove a system-mode rule
sudo beacon rules remove suspicious-egress-command --system

Flags

FlagDescription
--userUse per-user endpoint paths. Enabled by default
--systemUse system endpoint paths

beacon rules list

List active rules and rule ids.

beacon rules add

Install local rules into the store.