I'm deploying Traps and some users have detected that Traps is stopping a document signing proccess. Java.exe and jp2launcher.exe are the affected proccess. Also both proccess are unprotected.
I also have checked the EPM rules looking for a rule with the shell link module in notification mode. There is not a rule in notification mode.
Why is this happening?
I also tried to prevent them with a rule, but the detection continues in notification mode.
I can not understand what is happening.
Can anyone help me?
By default Java is monitored by suspicious or exploitation behavior, by default traps enable a rule for java like as another process, please check the reputation of those files (.exe) and if someone else are trying to use them.
The file detected is a link to the mail.
The detection is a false positive, and we want to exclude it. The problem is that the policies are being applied correctly (I can see the policy in the agent) but the detection is always in notification mode. There is no policy in notification mode. All default rules are in prevention mode, and also the ones that I'm creating are in prevention mode.
I also tried to disable all EPM to test it, and it still continues detecting the file (the plicy is being applied correctly).
I do not understand what is happening.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!