CREATE/MODIFY AT PROFILE LEVEL
-
On the Host Monitoring page, expand the profile and click Edit Allowlist
-
All processes are listed along with their Threat Intelligence, Path, Allowlisted libraries (if any), Source (Scan or Incident), Library Monitoring (Enabled/Disabled) and Allowlist (or not)
-
The “Not allowlisted” status is depicted below
-
The list displays Process Threat Intelligence. A mouse-over will display the details
-
A click on the process provides more information about it
-
The below table represents the different status values of process and/or library threat intelligence along with their descriptions
SL NO
Threat Intelligence Status
Color
Description
1
Safe
Green
If the executables are verified by the configured Threat Intelligence Service and are safe
2
Threat
Yellow
If the executable is marked as a potential threat
3
Unverified
Grey
If Threat Intelligence Service is not configured
4
Unknown
NA
If the reputation of the executable is not available with the configured Threat Intelligence Service
Table - Threat Intelligence Status
-
Select the Library/Script Auto Allowlisting option. This enables the automatic allowlisting of Safe only libraries OR all libraries OR none of the libraries depending on the selected drop-down
-
The Script Auto Allowlisting tab is populated when an ACP is applied to the profile
-
-
Select the required processes
-
Associated Libraries
-
Click the Allowlisted Libraries entry and select all the required libraries, click Close
-
Alternatively, select the appropriate Library Monitoring Option
-
-
The changed process is indicated as depicted below:
-
Click the required ALLOWLIST option
-
Click YES on the confirmation screen
NOTE:
Once the allowlist is edited, the changes are NOT published to the hosts immediately. Modifications are in draft state and MUST be published as described below
-
Publish/Discard the changes using the appropriate option. During the process of publishing, options of edit, delete, protection mode change or host association/disassociation are disabled
NOTE:
The library monitoring option is enabled for all the processes unless explicitly disabled on CMS
For the processes that get automatically updated, ensure that library monitoring is switched off to reduce the noise or incidents generated by them. A few examples of such processes are: taskeng.exe, googleupdate.exe, wmiprvse.exe