I am using VSE with ePO and I am unable to define blocking based on hash value without HIPS which is not deployed.
If I replace ePO-VSE with ENS, can I define block rules based on hash value?
Solved! Go to Solution.
@avilt You can use ENS Exploit Prevention Expert Rules to achieve this, yes. Please see the ENS Threat Prevention Product Guide PD27574 and Expert Rules Reference Guide PD27227, for more information.
Was my reply helpful?
If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?
ENS Access Protection rules can be created to prevent file execution by hash as well (e.g., PROCESSES subrule type and block the RUN operation for a Target Executable within a Subrule).
@avilt You can use ENS Exploit Prevention Expert Rules to achieve this, yes. Please see the ENS Threat Prevention Product Guide PD27574 and Expert Rules Reference Guide PD27227, for more information.
Was my reply helpful?
If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?
ENS Access Protection rules can be created to prevent file execution by hash as well (e.g., PROCESSES subrule type and block the RUN operation for a Target Executable within a Subrule).
Thank you
So with ENS, with antivirus product itself we will be able to achieve this objective without HIPS.
@avilt Yes, because ENS is a single platform, multi-module solution to allow for wider functionality under one product.
You can get started with the ENS FAQs article KB86704
Was my reply helpful?
If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?
Currently I see only 3 features (Antivirus, Firewall, Web Control)
How about white-listing and removable device control? How do I activate them?
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA