Data Center Security

 View Only
Expand all | Collapse all

difference between dcs event operation and disposition

  • 1.  difference between dcs event operation and disposition

    Posted Feb 13, 2017 01:24 AM

    HI All,

     

    What is differnce between dcs agent event operation and disposition .

    sometimes action is here disposition :- Denied and operation : allow

     

    Description                     Outbound Connection Allowed to 192.168.10.20:80 (http) from local address 192.168.10.113:49526
    Policy Name                     BH_sym_win_hardened_sbp
    Rule Name                       :i.SO
    Internal Rule                   Sandbox Outbound Access
    Process                         C:\PROGRAM FILES (X86)\VMWARE\INFRASTRUCTURE\VIRTUAL INFRASTRUCTURE CLIENT\LAUNCHER\VPXCLIENT.EXE
    Module Path                     C:\WINDOWS\SYSTEM32\WOW64CPU.DLL
    Disposition                     Allow
    Sandbox                         hardened_ps
    Operation                       Connect
    Protocol                        TCP
    Service Name                    http
    Local IP                        192.168.10.113
    Local Port                      49526
    Remote IP                       192.168.10.20
    Remote Port                     80
    Process ID                      196
    Thread ID                       5716
    Process Signature               Signed and Trusted  (00038407)
    Process Publisher               VMware, Inc.

     



  • 2.  RE: difference between dcs event operation and disposition

    Posted Feb 13, 2017 10:22 AM

    Dispostion will be be either Allow or Deny

    If the policy is set to Prevention Disabled (Log Only) then the Disposition will always be Allow

    The Operation is the call being made to the Windows API such as NtOpenKey to open a registry key, NtCreateFile to create or modify a file on the system, or Connect when a process is trying to communicate over the network.

     

    Please mark as SOLVED if this answers your question

     

    -Shane