Customer Systems Identification
Purpose: Identify systems discovered from the customer environment
Check the List: Review new systems found in discovery
Approve or Update: Confirm with customer or remove irrelevant items
Why Important: Minimizes noise of FalsePositive alerts.
Share discovered products with customer for validation and update the “Customer Systems” list.
The Customer Systems Identification feature is designed to detect and display systems discovered within a customer’s environment. These systems are surfaced through telemetry and need to be validated by the customer. This validation ensures that only legitimate, expected systems are included in the asset inventory, preventing false positives and misattribution in investigations.
Follow the path to view a list of “Customer Systems Identification - To Approve”.
In Navigator Window (Left side of the Arcsight)
Navigate to the “Resources” tab, and select “Lists”
Follow the path:
/All Active Lists/Mobula/Enrichment & Inventory/Customers Systems/Customer Systems Identification - To Approve
Right-click on the “Customer Systems Identification - To Approve” list and click “Show Entries”
The list will be opened in the “Viewer” window.
Here you will see all the customers and their products that have been discovered.
Send the discovered product list to the customer for confirmation of use.
Add the approved product to the Customer Systems list according to the relevant guide.
Delete the product from the Identified Systems list after it has been added to Customer Systems.
If the customer does not recognize or approve the product, simply delete it from the Customer Systems — it will automatically return to the Identified Systems list.
Find new products
Verify with the customer if its approved product
Add the product to the “Customer systems” to exclude False Positive alerts that way.
If the creation time column is older than 2 weeks we recommend deleting the entries and waiting up to 1 hour for the list to fill again with updated information.
Encourage customers to validate lists during onboarding and quarterly.
Periodically Check identified systems to approve them with the entity.
Lots of False Positive alerts.
Unvalidated systems may trigger unnecessary alerts.
The Customer Systems Identification – To Approve process is essential for maintaining an accurate and validated inventory of customer assets. By systematically reviewing discovered systems and confirming their legitimacy with the customer, platform managers help reduce false positives, improve alert accuracy, and strengthen operational efficiency. Regular validation cycles, clear communication with customers, and adherence to this process ensure that only approved systems are trusted — while unknown or outdated entries are promptly reviewed or removed. This proactive approach empowers SOC teams to focus on genuine threats, minimizing noise and maximizing protection.