Explanation of the "Executable verification Rule"
Last Modified: 2023-07-05 09:47:40 Etc/GMT
Affected Products
Languages:
This article is available in the following languages:
Trellix CEO, Bryan Palma, explains the critical need for security that’s always learning.
As per Gartner, "XDR is an emerging technology that can offer improved threat prevention, detection and response."
Trellix announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.
Trellix Advanced Research Center analyzes threat data on ransomware, nation-states, sectors, vectors, LotL, MITRE ATT&CK techniques, and emails.
After December 1, 2024, please log in to the Thrive Portal for support, knowledge articles, tools, and downloads. For information about using the Thrive Portal, view the Trellix Thrive Portal User Guide.
Explanation of the "Executable verification Rule"
Technical Articles ID:
KB90096
Last Modified: 2023-07-05 09:47:40 Etc/GMT Environment
Endpoint Security (ENS) Firewall 10.x Microsoft Windows Summary
The "Executable verification Rule" is added internally to Firecore when the "Block all untrusted executables" feature is enabled. The "Block all untrusted executables" feature blocks all executables that aren't signed or have an unknown Global Threat Intelligence (GTI) reputation. The "Executable verification Rule" rule is triggered when an executable that performs network communication is started. It validates the certificate of the signer and gets the reputation of the executable. NOTE: Make sure that the GTI server is reachable. For instructions, see KB53733 - Verify that GTI File Reputation is installed and endpoints can communicate with the GTI server. If the GTI server isn't reachable, the "Block all untrusted executables" feature doesn't block the application. When this rule is triggered, you see matches similar to the following in the Event: Traffic IP Address: x.x.x.x Description: xxx Path: xxx Message: xxx Matched Rule: Executable verification Rule Affected ProductsLanguages:This article is available in the following languages: |
|