Skip to main content
Migration Notice
We're migrating documentation from the old portal into this one. Some things may look a little different or out of place in the meantime — we know, and we're working to get it right. If something's unclear or doesn't look right, let us know.
Version: 2.14.1

Learning and Enforcement Mode

Introduction

Learning Mode allows the system to automatically adjust its behavior thresholds based on detected activity. When enabled, detections generate alerts and snapshots, but no lockouts occur. This is useful during initial deployment or when introducing new applications or service accounts.

How Long to Stay in Learning Mode

As a general guideline, plan to run Learning Mode for 2-4 weeks before switching to Enforcement Mode. Use this period to monitor alert volume and Historical Alerts, and extend it if you are still seeing a high rate of alerts for expected or normal activity at the end of that window.

Types of Learning Mode

  • Full Learning Mode: Applies learning to all users and events.
  • Monitor Mode List Learning: Applies learning only to users, paths, or IPs in the monitor mode list. Events outside that list may still trigger lockouts.

Enable Learning Mode

  1. Log in to the Eyeglass Web UI.
  2. Open the Ransomware Defender window.
  3. Go to Settings > Threshold.
  4. Select Automatically learn from events in monitor state.
  5. Click Submit.

Full Learning Mode

Leave the monitor mode list empty. Learning applies to every user and event the system sees, which gives the broadest baseline but also the longest settling period.

"Monitor Only List" Learning Mode

Add the specific users, paths, or source IP addresses you want to observe to the monitor mode list before enabling learning. Only those entries are learned; anything outside the list is still subject to lockout. See Monitor Only Settings for how to populate the list.

Monitor Learning Progress

While Learning Mode is active:

  • Snapshots may increase temporarily. Snapshots auto-expire after 48 hours.
  • Learned behavior thresholds appear in Settings > Learned Thresholds.
  • File extensions identified during learning are shown under Settings > File Filters, typically with status set to Disabled.

See Learning Mode Results

  1. Go to Settings > Learned Thresholds.
  2. Review the listed users, IPs, or paths.
  3. To remove a learned entry, click the Delete icon.
  4. To allow learned behavior, leave the entry in place.
  5. For file extensions, filter the list by typing Disabled to view those excluded from detection.

Disable Learning Mode

  1. Go to Settings > Thresholds.
  2. Uncheck Automatically learn from events in monitor state.
  3. Click Submit.

Learning stops. The system remains in Monitor Mode unless you switch to Enforcement Mode.

Know When to Enable Enforcement Mode

To determine readiness for Enforcement Mode:

  1. Go to Status > Event Detection Metrics.
  2. Review the Last 7 Days signal count. A target of fewer than 1 event per day is recommended.
  3. Compare with the Last 30 Days trend to confirm stability.

If event counts are still high, keep Learning Mode enabled to continue tuning.

Enable Enforcement Mode

Enforcement Mode locks out users when thresholds are exceeded. Only enable this mode once you have reviewed and accepted the learned thresholds and file filter settings.

  1. Go to Settings > Thresholds.
  2. Uncheck Monitor Mode.
  3. Click Submit.

You are now in Enforcement Mode. Detections may result in immediate or timed lockouts, depending on your configuration.