Showing results for 
Show  only  | Search instead for 
Did you mean: 
Level 9
Report Inappropriate Content
Message 1 of 2

Exploit Prevention Tuning

We are slowly enabling Exploit Prevention rules by reviewing the Would Block events.  Something I've noticed is that we are seeing Would Block events for files that we have already trusted in TIE.  Does Exploit Prevention not check TIE reputations first?

Example of would block event (Details removed):

Analyzer Rule Name:Malware Behavior: Windows EFS abuse

User ran C:\trustedfile.exe, which accessed C:\ProgramData\Microsoft\directory, violating the rule "Malware Behavior: Windows EFS abuse". Access was allowed because the rule wasn't configured to block.

1 Reply

Re: Exploit Prevention Tuning

It does not, because these rules often involve trusted files being exploited for malicious purposes.  You can use the exclusion option at the top of the policy, or in the case of the rules like you mention (any Process, file or registry rule), you can use their code as a baseline and rewrite it to include your own exclusions.  In the case of the one you reference below, I've done exactly that, to both expand coverage beyond the original rule and add my own false positives.


You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community