cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1111
Views
0
Helpful
1
Replies

LUA DAP script and ignore Defender

osiega001
Level 1
Level 1

the script (as supplied by cisco)

assert(function()
  for k,v in pairs(endpoint.am) do
    if(EVAL(v.activescan, "EQ", "ok", "string")and EVAL (v.lastupdate, "LT", "2592000", "integer"))
     then
             return true
         end
  end
  return false
end)()

 

My dap log: Sees both defender and BITDEFENDER how to solve this problem to get a TRUE value

 

DAP_TRACE[128]: dap_install_endpoint_data_to_lua:endpoint.am["362"]={}
DAP_TRACE: endpoint.am["362"] = {}
DAP_TRACE[128]: dap_install_endpoint_data_to_lua:endpoint.am["362"].exists="true"
DAP_TRACE: endpoint.am["362"].exists = "true"
DAP_TRACE[128]: dap_install_endpoint_data_to_lua:endpoint.am["362"].description="Windows Defender"
DAP_TRACE: endpoint.am["362"].description = "Windows Defender"
DAP_TRACE[128]: dap_install_endpoint_data_to_lua:endpoint.am["362"].version="4.18.1807.18075"
DAP_TRACE: endpoint.am["362"].version = "4.18.1807.18075"
DAP_TRACE[128]: dap_install_endpoint_data_to_lua:endpoint.am["362"].activescan="failed"
DAP_TRACE: endpoint.am["362"].activescan = "failed"
DAP_TRACE[128]: dap_install_endpoint_data_to_lua:endpoint.am["362"].lastupdate="4943059"
DAP_TRACE: endpoint.am["362"].lastupdate = "4943059"
DAP_TRACE[128]: dap_install_endpoint_data_to_lua:endpoint.am["362"].timestamp="1543477572"
DAP_TRACE: endpoint.am["362"].timestamp = "1543477572"
DAP_TRACE[128]: dap_install_endpoint_data_to_lua:endpoint.am["155"]={}
DAP_TRACE: endpoint.am["155"] = {}
DAP_TRACE[128]: dap_install_endpoint_data_to_lua:endpoint.am["155"].exists="true"
DAP_TRACE: endpoint.am["155"].exists = "true"
DAP_TRACE[128]: dap_install_endpoint_data_to_lua:endpoint.am["155"].description="Bitdefender Total Security"
DAP_TRACE: endpoint.am["155"].description = "Bitdefender Total Security"
DAP_TRACE[128]: dap_install_endpoint_data_to_lua:endpoint.am["155"].version="23.0.16.63"
DAP_TRACE: endpoint.am["155"].version = "23.0.16.63"
DAP_TRACE[128]: dap_install_endpoint_data_to_lua:endpoint.am["155"].activescan="ok"
DAP_TRACE: endpoint.am["155"].activescan = "ok"
DAP_TRACE[128]: dap_install_endpoint_data_to_lua:endpoint.am["155"].lastupdate="7745"
DAP_TRACE: endpoint.am["155"].lastupdate = "7745"
DAP_TRACE[128]: dap_install_endpoint_data_to_lua:endpoint.am["155"].timestamp="1548412886"
DAP_TRACE: endpoint.am["155"].timestamp = "1548412886"

1 Reply 1

mloraditch
Level 7
Level 7

Did you ever resolve this? I think I'm having the same issue?