10-22-2020 01:54 AM
Hello everyone,
I'm looking for a way to exclude a specific application (or a port) from an alarm or from the security event itself.
The reason is the "Windows Update Delivery" function causing Addr_Scan events resulting in Recon alarms.
I would like to discard these events by excluding the defined application or the specific port (7680/tcp).
As far as I know, there is no way to do so - maybe there is a possibility in the newer versions? (currently still on 7.0.3)
Thanks in advance.
Solved! Go to Solution.
10-22-2020 02:55 AM
I think you would be able to do that with version 7.3 which just came out last month.
10-22-2020 02:55 AM
I think you would be able to do that with version 7.3 which just came out last month.
10-22-2020 03:57 AM - edited 10-22-2020 04:02 AM
Thank you for the answer - we are already planning the upgradefor this version, I will give feedback once we are done.
I guess you are referring to the sub conditions mentioned in the 7.3 release notes regarding rules (page 11)?
10-22-2020 04:36 AM
You welcome, yes that's the one.
01-17-2021 05:48 PM
Hi, in version 7.3.0 in the SMC GUI go to Configure / Services, and click Add New, give it a Name (e.g. WUDO) and ports: 7680/tcp, and make sure to check the option "Exclude this service from the Worm Detection algorithm (Exclude Worm)".
Regards,
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide