Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
I am currently testing. I have an event (1000's) I want to create an exception to allow the activity, but the entry gives no specifics and the exception and behavior options of the wizard are greyed out.What do people do in this situation?
I have a client who does not want to stop users from installing applications but wants to protect against trojan/worms/rootkit etc.It would seem these two competing philosophies would not be easily inmplemented within CSA.Is there a base rule module ...
Is there a way to have the CSA agent service automatically start-up if an administrator stops the service?I know if an administrator logs in and stops the service and then logs out the service will start when the user logs out and back in.
We have a number of hosts who were in test mode, enabled full protection and then they move back into test mode within a day. There is no event generated and these hosts are part of a larger group of XP desktops that operate properly.TAC suggested u...
No user data - for real.Cannot do the protect mode - to early in the pilot and this is a very sensitive environment.My hunch is that this is good activity given it is running on a large portion of the installed base.
The actual event log message is below:TESTMODE: The process '' (as user ??) attempted to access the registry key 'MACHINE' and value ''. The attempted access was an open (operation = OPEN/KEY). The operation would have been denied.