Wanted to check is there any automated way we can use to disable specific signature ID in ENS exploit prevention rule for specific day and timing through server task or any other means.Once its disabled on specific day it should re-enable after 2 days.
I suggest to post this to ENS group.
I can repost it to ENS but since it has to deal with EPO for server task or etc thats why I posted in EPO
@haaris There is not a way to do this as an included feature within ENS Exploit Prevention policy (unlike HIPS Firewall where there are time based policy settings). Instead, you would have to acheive this via Policy Assignment Rules and Tagging. In which you would have to have an Assignment Rule based on tagging, and then a scheduled Server Task to apply the tag to the systems at the specified time, and and then send a wakeup call to enforce. Then, you'd have to have another Task to remove the tag when you no longer want the rule disabled.
This aspect does actually fall under ePO, as you originally believed.
Was my reply helpful?
If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?