07-04-2019 09:51 PM
Hi
so I have an application https://processhacker.sourceforge.io/ our dev guys want to use.
it shows up as begnin in wildfire, but its blocked signer override ???
OKay how / where is that configured I didn't do that.
Can I over ride
and how can I add in our companies signing cert
07-05-2019 11:24 AM - edited 07-05-2019 11:27 AM
The signer of this application is placed in Traps blacklisted signers; you would need to override this by whitelisting the signer Wen Jia Liu; but I would generally recommend not doing so unless you've fully analyzed the EXE and verified it isn't doing anything abnormal, as PAN is usually pretty good about actually only blocking known bad signers and that file doesn't have the best VirusTotal report.
edit:
To whitelist a signer go into your Malware profile and it'll be under the 'Examine Portable Executables and DLLs' section under "Whitelist Signers". DOCS
Just FYI I would recommend against whitelisting external signers. I would utilize the Whitelist Files function instead, so you can verify that whatever whitelisted EXE is actually secure.
07-05-2019 11:24 AM - edited 07-05-2019 11:27 AM
The signer of this application is placed in Traps blacklisted signers; you would need to override this by whitelisting the signer Wen Jia Liu; but I would generally recommend not doing so unless you've fully analyzed the EXE and verified it isn't doing anything abnormal, as PAN is usually pretty good about actually only blocking known bad signers and that file doesn't have the best VirusTotal report.
edit:
To whitelist a signer go into your Malware profile and it'll be under the 'Examine Portable Executables and DLLs' section under "Whitelist Signers". DOCS
Just FYI I would recommend against whitelisting external signers. I would utilize the Whitelist Files function instead, so you can verify that whatever whitelisted EXE is actually secure.
07-07-2019 02:47 PM
Hi
What I have done is over ridden the hash, happy with the file maybe not happy with the rest of the signed stuff.
Now a question about whitelisting certs.
Thats a text string and its regexed against certs ?
I can't find what is acceptable for that field.
can I do
^Wen Jia Liu$
or can I only do
Wen Jia Liu
does that mean that it will accept "Wen Jia Liu Reall Bad" as well or even "OWen Jia LiuS"
thanks
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!