01-11-2023 05:53 AM
Pretty simple need here....
Installing the latest version of WSUS Automated Maintenance from AJ Tek on our WSUS server and Cortex is blocking it with the description "Suspicious executable detected". How do I allow this to install? Is the best way to temporarily pause protection on the endpoint, install the software and then re-enable protection?
01-11-2023 06:38 AM
I think can depend how your environment is setup. you potentially could use the "report verdict as incorrect" in the incident... or could whitelist the hash... now if your setup to not allow unsigned app and that is unsigned that would be different. sorry for being slightly vague but some of this depends on your environment.
01-11-2023 11:05 AM - edited 01-11-2023 11:05 AM
Hi @cemcga
As suggested above, you can add files hashes to your allow list. Adding files to the block list or allow list takes precedence of any other policy rules that may have otherwise been applied to these files.
In order to add file hashes to your allow-lists:
You can read more about managing file execution here.
If this helped, please click Accept as Solution!
01-12-2023 07:27 AM
Thanks for this. To make sure I understand, this would allow the file to be executed on any endpoint, not just the one server, correct?
01-12-2023 07:41 AM
Yes, you are correct.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!