cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who Me Too'd this topic

Cortex does not block Windows binaries

L2 Linker

To mitigate cve-2022-30190 i wanted to add the file hashes of the msdt.exe binary to the blocklist; but with no effect until now.
The hashes occure in the logfile of the agent below hashcontrol as enabled, but verdict has a value "0".
Is it possible, that windows binaries are excluded from blocking by default?
i decided to block the binary for mitigation, because it's a minimal-invasiv approach, which can be reverted quickly if the issue is patched.

Who Me Too'd this topic