cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

ENS exploit prevention signature and powershell

Hi Heroes,

I saw in ENS expoit prevention signatures, there has some powershell related signatures and by default it's disabled. may I know for a best practice to protect against coinminner virus that invoke powershell to download malicious files, should we enable this signatures for powershell? or can you share your experience on this.

Thanks.

6 Replies

Re: ENS exploit prevention signature and powershell

Do you know the specific command line it uses?  Then we can put together a rule for it here. 

 

Dave

Re: ENS exploit prevention signature and powershell

Hi @Daveb3d Yes, I can see the command line by using Procmon tool, do you mean we can create an expert rule for it correct? as per the command line, looks like the virus is connecting to malicious site to download its executables and sorry currently i cant provide the command line.

 

Re: ENS exploit prevention signature and powershell

Ok..  is it using something like downloadstring or downloaddata in it?  If you can post the command line but remove the URI, that would be helpful.

 

Dave

Re: ENS exploit prevention signature and powershell

Hi @Daveb3d , I have sent you a private message for this. thanks.

Re: ENS exploit prevention signature and powershell

Responded!

Re: ENS exploit prevention signature and powershell

Thanks a lot!!! @Daveb3d 

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community