Disabling a specific signature ID under Exploit prevention in ENS through EPO Server task
Wanted to check is there any automated way we can use to disable specific signature ID in ENS exploit prevention rule for specific day and timing through server task or any other means.Once its disabled on specific day it should re-enable after 2 days.
Re: Disabling a specific signature ID under Exploit prevention in ENS through EPO Server task
@haaris There is not a way to do this as an included feature within ENS Exploit Prevention policy (unlike HIPS Firewall where there are time based policy settings). Instead, you would have to acheive this via Policy Assignment Rules and Tagging. In which you would have to have an Assignment Rule based on tagging, and then a scheduled Server Task to apply the tag to the systems at the specified time, and and then send a wakeup call to enforce. Then, you'd have to have another Task to remove the tag when you no longer want the rule disabled.
This aspect does actually fall under ePO, as you originally believed.
Was my reply helpful?
If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.