Greetings all,
I have been reviewing this link
https://docs.trellix.com/bundle/endpoint-security-10.7.x-product-guide-windows/page/GUID-F1025BE5-2E...
&
am still completely clueless on a how to create a expert rule at all....
I am simply trying to allow these blocks to not be blocked
it populates under
Event Description: Access protection rule violation detected and blocked
Threat Type: Self Protection
Module Name: Common
Source File Path: C:\Program Files\McAfee\Endpoint Security\Threat Prevention\blframeworku.dll
Source File Path: C:\Program Files\McAfee\Endpoint Security\Threat Prevention\LogLib.dll
Source File Path: C:\Program Files\McAfee\Endpoint Security\Threat Prevention\MfeAmsiProvider.dll
Source File Path: C:\Program Files\Common Files\McAfee\SystemCore\mfehida.dll
Source File Path: C:\Program Files\Common Files\McAfee\SystemCore\mfemmsa.dll
Source File Path: C:\Windows\System32\rsapwdfilt.DLL
Source File Hash: 1D925590C334F7A760F96D197011B9D2
Just some additional information:
Endpoint Security Threat Prevention>Access Protection>OFF
Endpoint Security Threat Prevention>Exploit Prevention>OFF
Any Help would be greatly appreciated....!!