cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

ENS Expert Rule Learning

Greetings all,

I have been reviewing this link 

https://docs.trellix.com/bundle/endpoint-security-10.7.x-product-guide-windows/page/GUID-F1025BE5-2E...

&

am still completely clueless on a how to create a expert rule at all....

I am simply trying to allow these blocks to not be blocked

it populates under

 

Event Description: Access protection rule violation detected and blocked 

Threat Type: Self Protection

Module Name: Common

Source File Path: C:\Program Files\McAfee\Endpoint Security\Threat Prevention\blframeworku.dll

Source File Path: C:\Program Files\McAfee\Endpoint Security\Threat Prevention\LogLib.dll

Source File Path: C:\Program Files\McAfee\Endpoint Security\Threat Prevention\MfeAmsiProvider.dll

Source File Path: C:\Program Files\Common Files\McAfee\SystemCore\mfehida.dll

Source File Path: C:\Program Files\Common Files\McAfee\SystemCore\mfemmsa.dll

 

Source File Path: C:\Windows\System32\rsapwdfilt.DLL

Source File Hash: 1D925590C334F7A760F96D197011B9D2

 

 

Just some additional information:

 

Endpoint Security Threat Prevention>Access Protection>OFF

Endpoint Security Threat Prevention>Exploit Prevention>OFF

 

 

Any Help would be greatly appreciated....!!

 

1 Reply
ktankink
Employee
Employee
Report Inappropriate Content
Message 2 of 2

Re: ENS Expert Rule Learning

Hi @davidharvey08  These events are related to the ENS Self-Protection functionality being triggered by a third party software DLL, which is trying to gain access into these ENS processes.  An Expert Rule is not necessary for this type of event.

This rsapwdfilt.DLL seems to be related to RSA Security software (after some Google searches), so the suggested course of action would be to configure this software to not attempt DLL injection into Trellix product processes, so I would suggest contacting that vendor for assistance with their product configuration.  Please reference this KB article for more details.

KB83123 - Compatibility issues can occur when third-party applications inject McAfee processes

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from product experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by employees.
Join the Community
Join the Community