cancel
Showing results for 
Search instead for 
Did you mean: 
Reliable Contributor haaris
Reliable Contributor
Report Inappropriate Content
Message 1 of 4

Disabling a specific signature ID under Exploit prevention in ENS through EPO Server task

Hi,

Wanted to check is there any automated way we can use to disable specific signature ID in ENS exploit prevention rule for specific day and timing through server task or any other means.Once its disabled on specific day it should re-enable after 2 days.

Labels (1)
Tags (1)
3 Replies
McAfee Employee hem
McAfee Employee
Report Inappropriate Content
Message 2 of 4

Re: Disabling a specific signature ID under Exploit prevention in ENS through EPO Server task

I suggest to post this to ENS group.

Was my reply helpful?

If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Reliable Contributor haaris
Reliable Contributor
Report Inappropriate Content
Message 3 of 4

Re: Disabling a specific signature ID under Exploit prevention in ENS through EPO Server task

Hi,

I can repost it to ENS but since it has to deal with EPO for server task or etc thats why I posted in EPO

McAfee Employee jess_arman
McAfee Employee
Report Inappropriate Content
Message 4 of 4

Re: Disabling a specific signature ID under Exploit prevention in ENS through EPO Server task

@haaris There is not a way to do this as an included feature within ENS Exploit Prevention policy (unlike HIPS Firewall where there are time based policy settings). Instead, you would have to acheive this via Policy Assignment Rules and Tagging. In which you would have to have an Assignment Rule based on tagging, and then a scheduled Server Task to apply the tag to the systems at the specified time, and and then send a wakeup call to enforce. Then, you'd have to have another Task to remove the tag when you no longer want the rule disabled.

image.pngimage.png

This aspect does actually fall under ePO, as you originally believed.

 

Was my reply helpful?

If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?

More McAfee Tools to Help You
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • Visit: Business Service Portal
  • More: Search Knowledge Articles
  • ePolicy Orchestrator Support
  • The McAfee ePO Support Center Plug-in is now available in the Software Manager. Follow the instructions in the Product Guide for more.