How to get sha value for each exe, dll, sys file which is getting blocked by Mcafee Solidcore. How to execlude any folder from centralized managed by ePO (Application control solidcore).
Solved! Go to Solution.
1. open ePO console
2. open Solidcore Events
3. open the relevant Solidcore Event
> here you can see the information
To continue from that event to create a rule:
4. select an event
5. press "actions" at the bottom of the page
6. select "exclude events" and that's where you will be guided through to create a rule
If you need more steps or guidance on how to do this, I would suggest calling Technical Support and asking for a remote session to assist you with this.
If you look at your Solidcore Events from within ePO, you'll see information such as MD5/ SHA of the certain file. From the Solidcore Event you can select actions > Exclude Events and you'll be guided through a setup to help you define a rule for that event.
I could not able to understand your suggestion. Could be provide step how to get SHA value for any exe, dll or sys file. Suppose some exe file is getting denied by Centralized EPO based Whitelisting application control. So how can I get SHA value and add same in EPO server to whitelist blocked exe file. If possible please provide me step to understand in better way.
1. open ePO console
2. open Solidcore Events
3. open the relevant Solidcore Event
> here you can see the information
To continue from that event to create a rule:
4. select an event
5. press "actions" at the bottom of the page
6. select "exclude events" and that's where you will be guided through to create a rule
If you need more steps or guidance on how to do this, I would suggest calling Technical Support and asking for a remote session to assist you with this.
Thanks for your support. It worked for me. Thank you very much.
in one of client PC windows 10 I am facing one more issue. Windows system is not getting boot and could not able to start windows itself after putting into enable mode from observed mode of solidcore. As soon as I restart windows 10 system after putting enabled mode from observed mode. When we put enable mode of solidcore after restart windows itself is not getting boot & could not able restart.
Hence I had to format all time. I tried 4 times all times facing same issue. always I had formatted & reloaded Windows OS. could you please suggest solution for this issue. I am using centralized Solidcore application control mcafee ePO based. Please suggest solution for this issue.
Have you tried to recover solidcore in these situations?
https://kc.mcafee.com/corporate/index?page=content&id=KB85958
You can change RTEModeonReboot = 2 instead of 0 and it should also boot if its whitelist related.
Please make sure you are using update 4. and following KB91257. If you need help we will need more information, we will need a MER, and a case in tech support to help you out. We may even require the full memory dump.
McAfee Support
Benjamin Ellis
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Windows 10 is in UEFI mode so could not able to run in safe mode & by changing RTEModeonReboot value it will change the mode of solidcore but any way I have to run in enable mode.
Could you please tell what could be the reason by changing observed to enable mode. Windows is not geeting bootup.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA