Hi,
We have few IOC (Indicators of compromise) hashes list, can we block them through Solidcore? As we have only VSE and Solidcore in our environment.
Solved! Go to Solution.
I believe VSE or ENS can block md5 but Solidcore can only block Sha-1 or sha-256 unless using Tie/gti, You can see this in the attribute feature or auth feature. or under executable files under solidcore rules
McAfee Support
Benjamin Ellis
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
VSE can't block MD5 hashes. ENS can do it but only within Access Protection. You would need a TIE server to set the reputation of any hashes which are PE files to malicious.
If something isn't being blocked by us though, the best route to take, would be to submit these unknown hashes to us so we can add coverage for the variant within our content.
what type of hash are they? Sha1/256/md5?
McAfee Support
Benjamin Ellis
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Hi Benjamin,
They are MD-5. Can we block MD-5?
If in case if we have SHA-1 and SHA-256 where to block them?
I believe VSE or ENS can block md5 but Solidcore can only block Sha-1 or sha-256 unless using Tie/gti, You can see this in the attribute feature or auth feature. or under executable files under solidcore rules
McAfee Support
Benjamin Ellis
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
VSE can't block MD5 hashes. ENS can do it but only within Access Protection. You would need a TIE server to set the reputation of any hashes which are PE files to malicious.
If something isn't being blocked by us though, the best route to take, would be to submit these unknown hashes to us so we can add coverage for the variant within our content.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA