Explanation of the McAfee Agent 5.x policy setting 'Self-Protection (Windows Only)'
Last Modified: 2023-08-11 04:41:59 Etc/GMT
Affected Products
Languages:
This article is available in the following languages:
Trellix CEO, Bryan Palma, explains the critical need for security that’s always learning.
As per Gartner, "XDR is an emerging technology that can offer improved threat prevention, detection and response."
Trellix announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.
Trellix Advanced Research Center analyzes threat data on ransomware, nation-states, sectors, vectors, LotL, MITRE ATT&CK techniques, and emails.
After December 1, 2024, please log in to the Thrive Portal for support, knowledge articles, tools, and downloads. For information about using the Thrive Portal, view the Trellix Thrive Portal User Guide.
Explanation of the McAfee Agent 5.x policy setting 'Self-Protection (Windows Only)'
Technical Articles ID:
KB82881
Last Modified: 2023-08-11 04:41:59 Etc/GMT EnvironmentMcAfee Agent (MA) 5.x
SummaryThe MA 5.x Extension includes the policy setting
When enabled, this setting prevents unauthorized access and changes to the MA 5.x Windows client files, folders, registry, and executables. This protection is beyond the security permissions set for MA folders and files during installation.
The new MA feature is similar to the Access Protection feature of VirusScan Enterprise (VSE). But, unlike VSE, there are no granular policy settings to allow, or only report tried access. The feature is designed to have the following two states, and only applies to Windows platforms with MA 5.x installed:
Currently, unauthorized access attempts aren't logged outside of a McAfee-specific log file. This means that access attempts by a non-trusted process are either of the following:
Lockdown of the MA services is available starting with MA 5.0.1.
Sometimes, you may need to disable self-protection for debugging purposes. Implement with caution and be fully aware of the risks involved. Disabling self-protection compromises MA security and can make it vulnerable to attacks. If you disable self-protection, do it only for a short duration, and then re-enable it. When self-protection is disabled, MA is still protected by the file and folder permissions set through the Windows Access Control List. But, when possible, you're advised to do the following:
For more information, see KB82740 - REGISTERED - How to temporarily disable self-protection for McAfee Agent 5.x in the McAfee Agent policy. Related Information
Locating Enterprise Documentation For product documents, go to the Product Documentation portal.
Contacting Trellix To contact Technical Support, go to the Create a Service Request page and log on to the ServicePortal.
Affected ProductsLanguages:This article is available in the following languages: |
|