Fairly new to Application control so forgive me if I am missing something but I have installed App Control 220.127.116.11 on and Endpoint and Solidified. Its running in Observe mode and has rebooted several times. I create a new script and execute it and nothing is displayed locally or in the Policy Discovery. If I set the Endpoint to Enabled Mode and re-run the script the script is blocked and the event is sent to Policy Discovery.
Am I doing something wrong?
Thank you for posting on the community.
If it is a simple execution without modification other binary files like installer file, the observation event for the Policy Discovery is not generated as designed.
I think the following KB helps you. In the Functionality section, you can see the table for events generated in workflow in Observe mode and Enable mode.
Ah thanks I see so for a file that would Deny Exec in Observe mode its just added to the Local WhiteList and no observation is registered.
So what if I am trying to create a baseline policy using a "known good" endpoint and want to make sure all files executed are added to ePO policy and not just the local whitelist? Or the reverse, I want to see what files are running in Observe mode so I can block certain scripts that should not be in use?
I am also struggling to find enough information on Script Interpreters. For example I want to assign an AD group to PowerShell so that anyone in the group can execute custom PowerShell scripts but I cant see how to do this.
I'm experiencing the same problem with events not getting generated in Observe mode in app control version 18.104.22.1685 and extension 22.214.171.124 (was told by support to upgrade the extension to resolve other issues we were having). The type of events I'm concerned with from the provided KB link are:
In our environment we were expecting to see an event get generated for software installations/uninstallations of apps that are not apart of the whitelist. Would this type of scenario fall under the event types I listed above? The product guide documentation isn't very easy to follow on this topic, but from what I can interpret, it seems like this scenario should generate an event in observe mode.