Hello McAfee,
so I just tested the new Rule 6157, which should detect the SMBGhost attacks.
It´s not working at all.
With the newest ENS, everything up to date, with TP and FW on a Win10 1909, when triggered remotely - McAfee ENS does NOTHING and the system goes down.
Trying with LPE, the rule again doesn´t trigger. TP only acts if AMSI is used. That´s a MS feature!!
I can provide to POCs if you want to have a look at it.
For all others: I can not recommend using this rule and feeling safe to be protected from SMBGhost attacks.
Can you Share the POC with us.
Please refer the article https://kc.mcafee.com/corporate/index?page=content&id=KB68030 and submit the same. Share the submission ID here and we will look into it.
Please share the analysis ID once the POC is submitted as mentioned in https://kc.mcafee.com/corporate/index?page=content&id=KB68030
Thank you.
Hi,
both POCs were taken from public available GIT repos.
I created a SR proving the POCs as well as to demonstrating videos:
4-20896044841
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: