Traps false positive

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Traps false positive

L4 Transporter

Hi,

 

We are having an issue with a file. This file can have several hashes  so its not possible to click in "treat as benign", besause the has file changes. SO what is the correct way to permit this file?

 

Thanks

10 REPLIES 10

Cyber Elite
Cyber Elite

@BigPalo,

If the file is in a set location you could simply whitelist the file itself via the file path, or if this is an in-house application EXE/DLL file you could have your developers sign the application so you can whitelist it based off of the signing certificate. 

 

How can we do that: If the file is in a set location you could simply whitelist the file itself via the file path?

 

The issue is that, WF lasts 10 minutes in permit the access to this file, so end-users first receive denied access, and then in 10 minutes end-user can open the file. But all en users open a ticket about this issue.

 

@BigPalo,

Directions differ based on the version of Traps you are using. Are you using the hosted Traps Management Service or are you still running the on-site Endpoint Security Manager? 

If the file name changes, you can whitelist the file path (with env. varablies if needed), and use a wildcard (*) for the file name. If the file name does not change, it would be advised to include the file name.

FIle name is the same, but the hashes are diferent. So can we create a white list for this filename?

@BigPalo ,

You can easily whitelist the file name; to give you directions on how to do so we need to know what Traps installation you are utilizing as the instructions will be different between TMS and ESM installations. 

Im almost sure that is ESM 4.x version.

@BigPalo 

 

You will need to make that decision. If several users are affected than you can make it global. If one person, or team, you can add just those machines or users to the rule.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!