cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Remotely creating or modifying Portable Executable

I have a few windows file servers that hold roaming profiles and re-directed folders. They are generating 100's of red flags for "Remotely creating or modifying Portable Executable, .INI, .PIF file types, and core system locations". Is there away to exclude the folders on these servers where users save their files?
4 Replies

Re: Remotely creating or modifying Portable Executable

Is that alert really of any value?   If you have ATP I wouldn't focus on it much.   Turn it off and run a daily report on any PE where DaysBeforeDetection = 0.  Much more useful. 

jess_arman
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 3 of 5

Re: Remotely creating or modifying Portable Executable

@countrybound I would agree with Daveb3d, that based on the description of the configuration of that sections of your environment, that particular rule does not sound to be suited/of much likely use to you. If you were to proceed as you've requested, it would make more sense to disable the rule for those systems, and proceed with an alternative like the one suggested.

User16096767
Reliable Contributor
Reliable Contributor
Report Inappropriate Content
Message 4 of 5

Re: Remotely creating or modifying Portable Executable

Is the recommendation is to disable not to report from Access Protection Policy?  Application team see these bunch of errors in Windows eventvwr. They are thinking its causing an issue. In Windows eventvwr that event is listed as an error instead of threat events. 

patrakshar
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 5 of 5

Re: Remotely creating or modifying Portable Executable

Hi @User16096767 

Are you specifically looking to disable the event within Event viewer? If so then then you can change this in common policy.

 

image.png

That will disable the event from going to windows event viewer. If you are looking to disable the event for the specific rule, then you have to disable the complete rule.

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community