Is there plans to add the SHA256 equivalent to the VSE/ENS products ?. By default its detecting as MD5.
is there any options to add IOCs to the VSE/ENS products ?. If yes how do we proceed.
Re: Infected files hash is displaying only MD5 values
Hi Shinoj ,
Thanks for your post,
Well at present, We have the only option to add the MD5 for the exe to add in VSE / ENS access protection rule to block and report.
Other MD5 value other exe process will be applicable even with VSE/ ENS access protection rule. However you can use the ENS exploit prevention expert rule to block the MD5 value like .txt .dll , lnk files as such.
I suggest you raise the PER with McAfee to check if the SHA256 or equivalent can be given as option.
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.