Various questions - Application Control (Solidcore) and more
I have a couple of questions concerning Application Control (Solidcore).
The version we use in my organization is 6.1.3.
My questions are as following:
Using the regular HIPS rules, I could only see which applications were used on a specific system, for example - I could only know that POWERSHELL.EXE was used, but I can't see what happened within the process (which scripts the user was running using that process and so on). My question is - is there a way to receive this information? Parhaps with Application Control logs, if using the right configuration?
Is it possible to somehow review commands & pieces of code that were used upon a Powershell ISE process?
Not necessarily regarding Application Control - is it possible to somehow monitor the behavior of Human Interface Devices (HIDs)? For example - monitor whether there are more than X keyboard types per second etc.
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.