Endpoint Protection

 View Only
  • 1.  System Lockdown after running checksum

    Posted Jul 18, 2013 04:16 AM

    Hello,

    I'm having a doubt regarding the System Lockdown functiontality.

    I ran the checksum utility on a target machine, for both C and D partition.
    Then I merged the text files and I imported it in Policies>File Fingerprint List, creating a new fingerprint list file. Everything worked fine.

    What I don't understand is why I continue to receive a lot of unapproved applications, even if I haven't added any new application.
    I can see these applications in Monitor>Logs>Application and Device Control and in Clients>Policies>System Lockdown>View Unapproved  Applications.

    Since the customer request is to lock the machine for permitting only approved application collected with checksum from an image, how can I resolve this issue?

    Thanks in advance,
    Alex.



  • 2.  RE: System Lockdown after running checksum

    Broadcom Employee
    Posted Jul 18, 2013 04:29 AM

    you would have run on one client, however if the other clients are running other applications you are bound to see this.



  • 3.  RE: System Lockdown after running checksum

    Posted Jul 18, 2013 04:37 AM

    Hi,

    thanks for answering.

    That's clear to me and the reason I was wondering what's wrong is because I have this behavior on a single machine.

    Do I miss something?

    Regards,

    Alex.



  • 4.  RE: System Lockdown after running checksum

    Posted Jul 18, 2013 07:02 AM

    The other likely issue is those processes are calling other processes which checksum does not capture. For instance, when Windows updates occur, many .TMP files can be created by the parent process.



  • 5.  RE: System Lockdown after running checksum

    Posted Jul 19, 2013 04:41 AM

    Thank you Brian,

    so, is there a way to avoid this behavior?

    Regards,

    Alex.

     



  • 6.  RE: System Lockdown after running checksum

    Posted Jul 19, 2013 09:45 AM

    Due to TMP files being dynamic, I'm afraid there is not much of an easier way aside from adding the necessary exception(s).