Data Loss Prevention

 View Only
  • 1.  Windows Defender - Runtimebroker.exe

    Posted May 23, 2019 07:56 PM
      |   view attached

    When we have Windows Defender enabled and using exploit protection on "runtimebroker.exe" to disable extention points, DLP's Endpoint Agent incidents are not picked up via the Print Channel. 

    Has anyone else run into this issue?   

    Thanks!



  • 2.  RE: Windows Defender - Runtimebroker.exe

    Posted Jun 20, 2019 05:42 PM

    Solved.   If you are using Defender with ATP, you must *not use high entrophy" on Randomize memory allocations (Bottom-up ASLR) for WDP.exe and EDPA.exe.