cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Highlighted
Level 11
Report Inappropriate Content
Message 1 of 3

Exploit prevention exclusions - rule specific

Jump to solution

Is there a way put an exclusion in place just for a specific rule rather than a blanket exclusion for everything.

Labels (1)
1 Solution

Accepted Solutions
Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 3

Re: Exploit prevention exclusions - rule specific

Jump to solution

Hello @Jmac24 

That depends on nature of the signature, please refer to:

*** Excluding items from Exploit Prevention
https://docs.mcafee.com/bundle/endpoint-security-10.6.0-threat-prevention-product-guide-windows/page...

for example, if signature belongs to "Files, processes, and registry" then you can not specify specific signature, however, if signature belongs to "Buffer Overflow and Illegal API Use" then you may specify which signature to exclude.

I hope this answers your question.


Was my reply helpful?

If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

View solution in original post

2 Replies
Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 3

Re: Exploit prevention exclusions - rule specific

Jump to solution

Hello @Jmac24 

That depends on nature of the signature, please refer to:

*** Excluding items from Exploit Prevention
https://docs.mcafee.com/bundle/endpoint-security-10.6.0-threat-prevention-product-guide-windows/page...

for example, if signature belongs to "Files, processes, and registry" then you can not specify specific signature, however, if signature belongs to "Buffer Overflow and Illegal API Use" then you may specify which signature to exclude.

I hope this answers your question.


Was my reply helpful?

If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

View solution in original post

Highlighted

Re: Exploit prevention exclusions - rule specific

Jump to solution

I'd like to follow up on that. I saw that there are many events for signature 6140:

Domain\User ran SourceFilePath\EXCEL.EXE, which accessed the process MSVBVM60.DLL, violating the rule "Attempt to load non-aslr dlls to bypass exploit mitigation techniques". Access was allowed because the rule wasn't configured to block.

Is there a way to exclude only the interaction where excel is accessing the specific DLL with the "Files, processes, and registry" exclusion, or do I need to exclude the DLL entirely for all signatures and all processes? The exclusion page is very confusing in this regard. Once I select the file\proc\reg one I am allowed to populate the following fields:

Name:

File name or path:

MD5 hash:

Signer:

Notes:

Does the "Name" field do anything or is it simply used to name the exclusion? I am asking, cause whatever I type in there, appears under the "Process name" column in the table afterwards. So as a conclusion, can I populate "excel.exe" under name and then "MSVBVM60.DLL" under file name or path, or this incorrect? Thanks!

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community