Module Name: Threat Prevention
Analyzer Content Version: 10.6.0.9845
Analyzer Rule ID: 6148
Analyzer Rule Name: Malware Behavior : Windows EFS abuse
We are seeing multiple detections/blocks on an executable accessing the following path:
C:\USERS\****\APPDATA\ROAMING\MICROSOFT\CRYPTO\RSA\S-1-5-21-516949104-117213805-3676103900-84242\1355BD1827B3BC5B5B33B489878EA3BC_B9E203E9-2786-4BF4-9D28-254942FE1E4A\
The rule was introduced on Jan 18th 2020 and is set to block and report. Is the recommendation from McAfee to remain in block or is it to write a specific exclusion?