05-06-2021 12:08 AM
Hello AMP Team,
Trying to understand the difference between AMP Exclusion and Application Whitelist.
When we would add an application/path or other
Solved! Go to Solution.
05-06-2021 01:25 AM
Hello @balakrishnanbipin1,
enclosed a short summary:
Greetings,
Thorsten
05-06-2021 01:25 AM
Hello @balakrishnanbipin1,
enclosed a short summary:
Greetings,
Thorsten
05-06-2021 01:57 AM
Thanks Thorsten for the details. Appreciate it.
Example : "HostMachine detected but did not block (Audit mode) access to lsass.exe by MicrosoftDependencyAgent.exe"
To be more clear, if I have to Whitelist the Microsoft DependencyAgent, I did a right click and add to Application Whitelist in Outbreak filter. Is this a recommended solution or would I need to add the hash value under Exclusion System Process Exclusion
Need your advice.
05-06-2021 05:07 AM
Hello @balakrishnanbipin1,
it depends what was exactly detected and which Threat Type was detected. If you add the Application (hash) to the whitelist.
What Event Type have you seen in your console?
05-06-2021 06:52 AM
Hi,
That's a System Process Execution.
04-20-2022 05:06 AM
Hi Thorsten,
could you help me with issue we are facing? We use PatchMyPC-ScriptRunner.exe tool for software deployment/checks and this tool is creating a records in the registry similar to:
\MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\XYZ.exe
Cisco CSE is generating events due to the registry changes - The registry was updated to add a debugger to the key: Image File Execution Options.
Is there any way how to either mute or whitelist this activity? We have confirmation that usage of this tool is needed and necessary and that it is legitimate tool.
I've tried to add the hash to the application whitelist + create file scan exclusion, but we still receive events. Based on the event the detection was made by behavioral engine.
I would appreciate any help.
thanks
marcel
04-21-2022 03:54 AM
Hello @jmarcel2 ,
I assume the Backend is generating CloudIOC events here. If this is the case, you may open a TAC case, so we add an exclusions for you. BTW, we are already working on a solution, so customers can generate CloudIOC exclusions.
Greetings, Thorsten
05-06-2021 05:14 AM
09-05-2021 12:43 PM
Can I whitelist some specific application to run, and block everything else!!
09-06-2021 04:19 AM
Hello @Sky.w3lker,
no, such application management or integrity monitoring is actually out of focus for Secure Endpoint.
Greetings,
Thorsten
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide