Endpoint Protection

 View Only
  • 1.  avoid creating a windows service application and device control in SEP

    Posted Sep 24, 2013 12:24 PM

    good

    They can tell you how we can avoid creating a service in windows aplication with policy control and device SEP

    thank you very much



  • 2.  RE: avoid creating a windows service application and device control in SEP

    Posted Sep 24, 2013 12:27 PM

    I'm not sure what you mean, can you elaborate? Are you talking exceptions for ADC?



  • 3.  RE: avoid creating a windows service application and device control in SEP

    Posted Sep 24, 2013 12:35 PM

    Hi Brian

     

    for example we want to avoid creating the CRDRVPS named service, we could do preventing registry keys are created,

    when trying to create a service that must create or modify the registry keys

     

    Thanks



  • 4.  RE: avoid creating a windows service application and device control in SEP

    Trusted Advisor
    Posted Sep 24, 2013 12:57 PM

    Hello,

    Are you talking about hardening the SEP to increase security - 

    Check these Articles:

    Hardening Symantec Endpoint Protection (SEP) with an Application and Device Control Policy to increase security

    http://www.symantec.com/docs/TECH132337

    How the Application and Device Control Hardening policy works

    http://www.symantec.com/docs/TECH132307

    SEP Application Control policy to protect executable file registry configuration

    http://www.symantec.com/docs/TECH171301

    How to protect systems with SEP from an autorun.inf that links to malware.

    http://www.symantec.com/docs/TECH201440

    Hope that helps!!



  • 5.  RE: avoid creating a windows service application and device control in SEP

    Posted Sep 24, 2013 03:21 PM

    You could just create the rule but exclude the specific reg keys from applying to that rule.



  • 6.  RE: avoid creating a windows service application and device control in SEP

    Posted Sep 24, 2013 06:30 PM

     

    hello

    could also avoid creating a file, it would be possible with the SEP,
    for example want to avoid creating the file test.exe
    how could I?

    Thanks



  • 7.  RE: avoid creating a windows service application and device control in SEP

    Posted Sep 24, 2013 09:55 PM

    Just follow this example:

    http://www.symantec.com/docs/TECH185907