cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
JKdc
Level 9
Report Inappropriate Content
Message 1 of 3

Access Protection Rule Clarification

I inherited most of our AP rules and I find all of the rules for the main executable use the * wildcard for all executables. Then in the subrules, the file path directly to the .exe file is placed as a file type instead of a process type. I've been copying that pattern, but I don't think I'm doing it right.

 

If the rule is trying to block a specific .exe, should I only include it in the main 'executables' field for the rule? I would not need to create a separate subrule then, correct?

If it's a non-exe file I'm trying to block, then I would use the wildcard executable and put the file name in the subrule, correct?

For the file type, if a 'file' was specified to block executing, but it points to a .exe does it do essentially the same thing if I set the type as 'process' and blocked execution?

2 Replies
AjaySundar
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 3

Re: Access Protection Rule Clarification

Hi @JKdc,

Good day to you!

The way that you have been implementing the AP rules seems to be right. We would recommend testing it first and then implementing it. The post below has steps to block the execution of any file.

https://community.mcafee.com/t5/Endpoint-Security-ENS/How-to-block-an-exe-file-using-Access-Protecti...

Please check and let me know if it was helpful.

Regards,

Ajay

JKdc
Level 9
Report Inappropriate Content
Message 3 of 3

Re: Access Protection Rule Clarification

The rules seem to be doing the job OK. My only real concern, I guess, is if there's really any difference when trying to block a .exe file if I define it as a "file" and block execution/read/write or if I define it as a "process" and block running of it. Thanks.

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community