I have luckily drawn the short straw and have been handed a project to protect some data. I am trying to implement this through HIPS. I need to be able to read all of the data from this special folder, block writes, and block the data from being copied from this special folder to all locations except local drives. There are two exceptions two this rule. They should be able to write to two subfolders within the special folder and local drives. I can get the rule to trigger in the HIPS console just fine. Now I am working on the exceptions. Where would I put in the exceptions for all local drives and "SpecialFolder1" and "SpecialFolder2" to allow them to write these files to those locations.
I got the two folders excluded, but still cannot manage to exclude local hard drives.
You aren't able to do a few of the things you are talking about. First, you are not going to be able to "read" all data from your folder, via HIPS. Second, you cannot block copies to selected drives. For the purposes of HIPS Custom Signatures, you are basically limited to directives of execute, write, create, etc.
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.