Traps false positive

Reply
Highlighted
L4 Transporter

Traps false positive

Hi,

 

We are having an issue with a file. This file can have several hashes  so its not possible to click in "treat as benign", besause the has file changes. SO what is the correct way to permit this file?

 

Thanks

Highlighted
Cyber Elite

@jesuscano,

If the file is in a set location you could simply whitelist the file itself via the file path, or if this is an in-house application EXE/DLL file you could have your developers sign the application so you can whitelist it based off of the signing certificate. 

Highlighted
L4 Transporter

 

How can we do that: If the file is in a set location you could simply whitelist the file itself via the file path?

 

The issue is that, WF lasts 10 minutes in permit the access to this file, so end-users first receive denied access, and then in 10 minutes end-user can open the file. But all en users open a ticket about this issue.

 

Highlighted
Cyber Elite

@jesuscano,

Directions differ based on the version of Traps you are using. Are you using the hosted Traps Management Service or are you still running the on-site Endpoint Security Manager? 

Highlighted
L4 Transporter

If the file name changes, you can whitelist the file path (with env. varablies if needed), and use a wildcard (*) for the file name. If the file name does not change, it would be advised to include the file name.

Highlighted
L4 Transporter

FIle name is the same, but the hashes are diferent. So can we create a white list for this filename?

Highlighted
Cyber Elite

@jesuscano ,

You can easily whitelist the file name; to give you directions on how to do so we need to know what Traps installation you are utilizing as the instructions will be different between TMS and ESM installations. 

L4 Transporter

Im almost sure that is ESM 4.x version.

Highlighted
L4 Transporter
Highlighted
L4 Transporter
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!