cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Marvin
Level 8
Report Inappropriate Content
Message 1 of 2

ENS 10 - Creating a rule to block running a program

Jump to solution

Hi,

I have an issue with an infected process starting a system EXE and I'd like to be able to detect & block this.

I'd like to create a rule that does something like 

MyDomain\MyUser ran C:\Program Files\PROGRAM.EXE, which accessed the process C:\Windows\REGEDIT.EXE, violating the rule "XXXXXXX", and was blocked.

Can someone help me?

 

1 Solution

Accepted Solutions
AdithyanT
Employee
Employee
Report Inappropriate Content
Message 2 of 2

Re: ENS 10 - Creating a rule to block running a program

Jump to solution

Hi @Marvin,

Thank you for your post.

Please Create an Access Protection rule where process/executable is the malicious/undesirable process.

Please go to sub rule and select type as "process" and add the "System" process as the target.

Ensure the action in the sub rule is selected as "execute" and the action for the rule i set to Block and Report.

I would generally recommend trying the rule with "Report" ONLY and then, once you confirm it is working, please select Block option as well.

Additionally, I sincerely hope this KBA helps as well:

https://kc.mcafee.com/corporate/index?page=content&id=KB86577

The above KBA is for situations where the target is a File or Registry, in your case, it is a process.

Was my reply helpful?
If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!

Thanks and regards,
Adithyan T

View solution in original post

1 Reply
AdithyanT
Employee
Employee
Report Inappropriate Content
Message 2 of 2

Re: ENS 10 - Creating a rule to block running a program

Jump to solution

Hi @Marvin,

Thank you for your post.

Please Create an Access Protection rule where process/executable is the malicious/undesirable process.

Please go to sub rule and select type as "process" and add the "System" process as the target.

Ensure the action in the sub rule is selected as "execute" and the action for the rule i set to Block and Report.

I would generally recommend trying the rule with "Report" ONLY and then, once you confirm it is working, please select Block option as well.

Additionally, I sincerely hope this KBA helps as well:

https://kc.mcafee.com/corporate/index?page=content&id=KB86577

The above KBA is for situations where the target is a File or Registry, in your case, it is a process.

Was my reply helpful?
If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!

Thanks and regards,
Adithyan T
You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from product experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by employees.
Join the Community
Join the Community