Advanced Threat Protection

 View Only
Expand all | Collapse all

Created an exception but SEP still flags the file

Migration User

Migration UserJun 20, 2017 02:04 PM

ℬrίαη

ℬrίαηJun 20, 2017 02:05 PM

ℬrίαη

ℬrίαηJun 26, 2017 07:11 PM

Migration User

Migration UserJun 26, 2017 07:57 PM

ℬrίαη

ℬrίαηJun 26, 2017 08:10 PM

  • 1.  Created an exception but SEP still flags the file

    Posted Jun 20, 2017 01:15 PM

    Hi, 

     

    We are running SEPM on a 2k12 VM, User that has a problem is on Win10pro system running SEP

    I have a user that has Cygwin tools that specifically has netcat and SEP is flagging & quarantining netcat (nc.exe)  I realize the security risks but this user cannot do his work.  

    I went under policies> exceptions> exceptions policy -workstation > right clicked edit> then hit exceptions> add exception.  

    120px_symantecfoto.png

     

    Anyways, that exception was created about a week ago.  The user has been in the office has synced up to the server and pulled down the new policies but still says that SEP is blocking it.  I have confirmed his statement by creating a VM and replicating his environment and SEP also blocks nc.exe for me as well.

     

    Thanks in advance for all of the help and I apologize if I do not post in the correct section, first time poster.  



  • 2.  RE: Created an exception but SEP still flags the file

    Posted Jun 20, 2017 01:21 PM

    I can't see the screenshot but can you verify which component is blocking it? If a component other than AV is blocking it, such as SONAR, and you added the exception for AV than this could be the reason. Also, did you verify the client has the same policy as what the SEPM shows?



  • 3.  RE: Created an exception but SEP still flags the file

    Posted Jun 20, 2017 01:55 PM

    sep1.pngYes, all of the policies and such match.  This is from my test VM.  



  • 4.  RE: Created an exception but SEP still flags the file

    Posted Jun 20, 2017 02:01 PM

    Did you add the exact path to the file or did you just add the file name?



  • 5.  RE: Created an exception but SEP still flags the file

    Posted Jun 20, 2017 02:04 PM

    Just added the file name.  



  • 6.  RE: Created an exception but SEP still flags the file

    Posted Jun 20, 2017 02:05 PM

    Needs to be the full path to the file.



  • 7.  RE: Created an exception but SEP still flags the file

    Posted Jun 20, 2017 02:50 PM

    I edited the current exception with the full path to the file.  I'm on the test VM and have done live update and update the policy but I'm still receiving the same error.  Is there a period of time I should be waiting for the new policies to sync up? 



  • 8.  RE: Created an exception but SEP still flags the file
    Best Answer

    Posted Jun 20, 2017 02:58 PM

    There is no reason to run liveupdate as that just grabs the latest content and has nothing to do with exceptions.

    The client should pick up the policy change next time it heart beats in.

    It may be easier to add this to the policy via the risk log. I can barely read the screenshot. You can follow the steps outlined here:

    http://www.symantec.com/docs/HOWTO80928

    Just go into your SEPM and go to the Monitors page >> Logs tab

    Set the Log type to Risk put a check in the box next to the detection and select the + and allow application, select the pol.icy you want to add it to and click Save Changes



  • 9.  RE: Created an exception but SEP still flags the file

    Posted Jun 20, 2017 07:49 PM

    I took your last post and made it happen. However I'm still getting the same results.  I'll check back in the morning.  I'm still not sure when the new policy is pulled from the server.  Thanks for your help so far.  



  • 10.  RE: Created an exception but SEP still flags the file

    Posted Jun 21, 2017 12:17 PM

    Ok so the actions taken yesterday don't work.  SEP on my VM still blocks nc.exe.  Anything else I can try? 



  • 11.  RE: Created an exception but SEP still flags the file

    Posted Jun 21, 2017 12:22 PM

    May just need to open a support case so someone can get on your machine. This typically isn't this problematic assuming the client can connect to the SEPM and grab policy updates and you added exceptions per the link.



  • 12.  RE: Created an exception but SEP still flags the file

    Posted Jun 26, 2017 06:02 PM

    Sorry for the late reply but I got it to work finally.  Created a exception from log.  Last question is there a way to not have the alert pop up on the user's screen? 



  • 13.  RE: Created an exception but SEP still flags the file

    Posted Jun 26, 2017 06:09 PM
      |   view attached

    In the AV policy on the Auto-Protect >> Notification tab just uncheck the option:

     



  • 14.  RE: Created an exception but SEP still flags the file

    Posted Jun 26, 2017 06:53 PM

    Creating an exception though the log file worked.  Thank you.  Last question is there a way to stop the notifications that pop up everytime my user tries to use the system for nc.exe? 



  • 15.  RE: Created an exception but SEP still flags the file

    Posted Jun 26, 2017 07:11 PM
    Yes, see my post above.


  • 16.  RE: Created an exception but SEP still flags the file

    Posted Jun 26, 2017 07:57 PM

    Sorry did not see that.  Thanks again.  



  • 17.  RE: Created an exception but SEP still flags the file

    Posted Jun 26, 2017 08:10 PM

    Happy to help out, you're welcome.