Endpoint Protection

 View Only
Expand all | Collapse all

Exclusion using file fingerprint

pete

peteFeb 08, 2012 11:51 AM

  • 1.  Exclusion using file fingerprint

    Posted Feb 08, 2012 09:18 AM

    Hi,

     

    How do you exclude files based on file finger-print?

     

    N.Ra



  • 2.  RE: Exclusion using file fingerprint

    Trusted Advisor
    Posted Feb 08, 2012 09:27 AM

     

    Hello,

    Creating an Exception specifically with File fingerprint is not possible.

    However, there are other exceptions, which could be created with help of File fingerprint

    Check this Article for SEP 12.1:

    Creating exceptions for Symantec Endpoint Protection

    You can only do it with system lockdown or using an application control policy.

    Hope this Helps!!



  • 3.  RE: Exclusion using file fingerprint

    Broadcom Employee
    Posted Feb 08, 2012 09:32 AM

    is it for system lockdown?

    check this link and let know if it helps

    http://www.symantec.com/business/support/index?page=content&id=HOWTO55133



  • 4.  RE: Exclusion using file fingerprint

    Posted Feb 08, 2012 09:44 AM

    So this can be done only with the help of ADC?

    These are servers and we have disabled PTP & NTP on these machines...... I was under the impression that we can somehow use CE policy for this.....



  • 5.  RE: Exclusion using file fingerprint

    Broadcom Employee
    Posted Feb 08, 2012 09:59 AM

    check this link to create a file fingerprint list. You can use the checksum.exe for the same

    http://www.symantec.com/business/support/index?page=content&id=HOWTO55451



  • 6.  RE: Exclusion using file fingerprint

    Posted Feb 08, 2012 10:01 AM

    Hi NRaj,

     

    Can you tell us what exactly you are trying to achieve? Do you want to exclude a particular file from scanning?



  • 7.  RE: Exclusion using file fingerprint

    Broadcom Employee
    Posted Feb 08, 2012 10:51 AM

    where did you see file fingerprint undr exception?

    the above articles were related to system lockdown not for exception from scan.



  • 8.  RE: Exclusion using file fingerprint

    Posted Feb 08, 2012 11:11 AM

    I did not see fingerprint under exception. I was asking how to exclude files using their hash value, if it is under ADC. I do not wanna do a system lockdown. I have also explained my situation, if you see an alternative, lemme know.



  • 9.  RE: Exclusion using file fingerprint

    Broadcom Employee
    Posted Feb 08, 2012 11:17 AM

    ADC is used application and device control, it has nothing to do with scan exception.



  • 10.  RE: Exclusion using file fingerprint

    Broadcom Employee
    Posted Feb 08, 2012 11:28 AM

    you can exclude the application scan exception.Hope that might help.



  • 11.  RE: Exclusion using file fingerprint

    Posted Feb 08, 2012 11:38 AM

    App scan is only available in 12. We are running 11.07 (no upgrade in near future). I perfectly understand that ADc is for appln & device exclusion & not for scan. If the process in question is an application and if that can be excluded using the file's finger print, won't that help?

     

    Is it possible to do an exception based on hash value?



  • 12.  RE: Exclusion using file fingerprint

    Broadcom Employee
    Posted Feb 08, 2012 11:45 AM

    ahh!! there is no way to put the exception using exception as far i know. you can put under IDEA.



  • 13.  RE: Exclusion using file fingerprint

    Posted Feb 08, 2012 11:50 AM

    Hmm..... Okay. But what is IDEA? you mean the enchancement request?



  • 14.  RE: Exclusion using file fingerprint

    Broadcom Employee
    Posted Feb 08, 2012 11:51 AM

    yes :-)



  • 15.  RE: Exclusion using file fingerprint

    Posted Feb 08, 2012 12:10 PM

    My issue does not seem to have a solution apart from the workarounds mentioned here....Thank you all for your time. 



  • 16.  RE: Exclusion using file fingerprint

    Posted Feb 15, 2012 10:04 AM

    These servers need to exclude few processes from being scanned. Since we have PTP & NTP disabled on servers, there is no point in excluding processes as processes (truscan) are a part of PTP which is disabled. So instead of the processes, we are trying to exclude the files using the file path.

    But because of the huge number of servers, and the different locations where these applications are installed, the total number of exclusions came to 22,000. There are only 94 processes, but when the locations are considered, its number increases. So we thought we can exclude them using the file fingerprint exclusion option which i am not familiar with. If you can suggest a different option, it would be great. Thanks.



  • 17.  RE: Exclusion using file fingerprint
    Best Answer

    Posted Feb 27, 2012 11:16 AM

    File fingerprint or hash value based exceptions are not supported in Centralised Exception policy. Since you are using SEPM ver 11.0.7 even application based exceptions are not supported. As PTP is not installed the ADC option also ruled out. So if you are not planning to upgrade then the only way is to exclude as a file in the CE policy. I know it's really difficult to configure 22K exceptions. If possible check once again and remove the unwanted exceptions then configure it.