Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Report

Created: 30 Jan 2012 | 5 comments
SKP's picture
0 0 Votes
Login to vote

Can we able to find out by reports,what all the software are installed in SEP client system & block unauthorized software.

Comments

kavin's picture
30
Jan
2012
0 Votes 0
Login to vote

Yes you can enable the

Yes you can enable the feature for "Application learning" and with the help of the learned application list you can find out what all applications are running on the client where SEP is installed.

With the help of system Lockdown feature you can block unwanted software from running

Note :- Test these things before you do it in the production

Simpson Homer's picture
30
Jan
2012
1 Vote +1
Login to vote

You woudl be able to get

You woudl be able to get these reports via System Lock down Feature, You can configure the logging system on one machine and you would get reports for all that your looking for.

Please refer to this article:-

 

 

Configuring system lockdown

 

https://www-secure.symantec.com/connect/forums/report-2

pete_4u2002's picture
30
Jan
2012
1 Vote +1
Login to vote

Application Learning allows

Application Learning allows Symantec Endpoint Protection (SEP) clients to report information and statistics about the executables that are run on them. This information is provided to the Symantec Endpoint Protection Manager (SEPM) and aggregated into the SEPM database. The purpose of this information is to build a list of known applications in an environment to create Application-based firewall rules, Host Integrity (HI) rules and can be used as a reference for developing Application Control rules and Centralized Exceptions

check this link

http://www.symantec.com/business/support/index?page=content&id=TECH134367

once identified you can set for systemlockdown using this link

 Enabling system lockdown to block unapproved applications

http://symantec.com/docs/HOWTO55132

greg12's picture
30
Jan
2012
1 Vote +1
Login to vote

Application Control

I agree with Pete to use Application learning. However, System Lockdown can be dangerous (if your whitelist doesn't span all necessary applications, the client may freeze), but even if it works, it's cumbersome to maintain because you constantly have to add new approved applications. For example, every browser patch must be added to the System Lockdown whitelist.

Perhaps it's better you forbid the unauthorized software through Application Control rules. See this PDF document: http://www.symantec.com/connect/sites/default/files/Configuring_Application_Control_1.1.pdf

Ian_C.'s picture
30
Jan
2012
0 Votes 0
Login to vote

Orange List

Yip, have to agree with you.

Every patch will update the checksum of the EXE. And then you have to remember to clean out the old difinitions because the software has been retired or is insecure.

That's why these guys talk about an Orange list. https://www-secure.symantec.com/connect/videos/better-approach-white-listing

PS Never used the software, I just like the idea.