My organization is in the planning stage of implementing MACC. This is a project I have inherited, and it looks like someone had already started building a whitelist. I'm not very familiar with this product. I've gone through the product guide, which is helpful, but I'm still not sure what to do.
I have a few devices currently in observe mode. I just deployed Solidcore to another device. As it was going through the solidification process, there were several alerts with the following:
McAfee Solidifier prevented an attempt to modify file 'C:\WINDOWS\system32\DRIVERS\swin.sys' by process/script C:\Windows\System32\rphcp.exe
Isn't swin.sys the Solidifier driver and rphcp.exe the security sensor?
The event viewer on the device shows:
Description McAfee Application Control prevented an attempt to modify this file because this file is whitelisted. To make changes to whitelisted files, define a policy with the relevant rules.
Event Display Name File Write Denied
Event File Name C:\WINDOWS\system32\DRIVERS\swin.sys
Event Generated Time 10/22/20 7:56:23 AM CDT
Event ID 20719
Event Name WRITE_DENIED
Event Sequence Number 2
Generated by an Updater No
Generated in an Update Window No
Performed By NT AUTHORITY\SYSTEM
Process ID 5164
How can I fix this? It looks like it's appearing on a few of the test endpoints but not all of them.
Solidcore 8.3.0
ePolicy Orchestrator 5.10.0 (Build 2428)
Windows 10 1909 Enterprise