Is there a way put an exclusion in place just for a specific rule rather than a blanket exclusion for everything.
Solved! Go to Solution.
Hello @Jmac24
That depends on nature of the signature, please refer to:
*** Excluding items from Exploit Prevention
https://docs.mcafee.com/bundle/endpoint-security-10.6.0-threat-prevention-product-guide-windows/page...
for example, if signature belongs to "Files, processes, and registry" then you can not specify specific signature, however, if signature belongs to "Buffer Overflow and Illegal API Use" then you may specify which signature to exclude.
I hope this answers your question.
Hello @Jmac24
That depends on nature of the signature, please refer to:
*** Excluding items from Exploit Prevention
https://docs.mcafee.com/bundle/endpoint-security-10.6.0-threat-prevention-product-guide-windows/page...
for example, if signature belongs to "Files, processes, and registry" then you can not specify specific signature, however, if signature belongs to "Buffer Overflow and Illegal API Use" then you may specify which signature to exclude.
I hope this answers your question.
I'd like to follow up on that. I saw that there are many events for signature 6140:
Domain\User ran SourceFilePath\EXCEL.EXE, which accessed the process MSVBVM60.DLL, violating the rule "Attempt to load non-aslr dlls to bypass exploit mitigation techniques". Access was allowed because the rule wasn't configured to block.
Is there a way to exclude only the interaction where excel is accessing the specific DLL with the "Files, processes, and registry" exclusion, or do I need to exclude the DLL entirely for all signatures and all processes? The exclusion page is very confusing in this regard. Once I select the file\proc\reg one I am allowed to populate the following fields:
Name:
File name or path:
MD5 hash:
Signer:
Notes:
Does the "Name" field do anything or is it simply used to name the exclusion? I am asking, cause whatever I type in there, appears under the "Process name" column in the table afterwards. So as a conclusion, can I populate "excel.exe" under name and then "MSVBVM60.DLL" under file name or path, or this incorrect? Thanks!
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA