SC: Run commands stop when policy enforcement occurs
Last Modified: 2024-01-31 08:45:43 Etc/GMT
Affected Products
Languages:
This article is available in the following languages:
Trellix CEO, Bryan Palma, explains the critical need for security that’s always learning.
As per Gartner, "XDR is an emerging technology that can offer improved threat prevention, detection and response."
Trellix announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.
Trellix Advanced Research Center analyzes threat data on ransomware, nation-states, sectors, vectors, LotL, MITRE ATT&CK techniques, and emails.
After December 1, 2024, please log in to the Thrive Portal for support, knowledge articles, tools, and downloads. For information about using the Thrive Portal, view the Trellix Thrive Portal User Guide.
SC: Run commands stop when policy enforcement occurs
Technical Articles ID:
KB91353
Last Modified: 2024-01-31 08:45:43 Etc/GMT Environment
Application and Change Control (ACC) 8.2.1.143, 8.0.2.228 and later
Problem
SC: Run commands stop if policy enforcement occurs while the task is running. For example, resolidifying a system through the SC: Run command Cause
In versions before 8.0.2.228, the command-line interface (CLI) enters a hung state waiting on a command to return a response to the IPC channel. All other commands aren't allowed to run during this time. ACC 8.0.2.228 and later include a feature that fails a command when the CLI has to wait longer than expected. Failing the command allows policy enforcement to be prioritized. In ePolicy Orchestrator (ePO), the Solution
Create an Application Control Client task (SC: Run command) using the following:
so config set MaplCommLostRestart=5 eu This task sets the retry time on the command to 0 during the solidification. This setting prevents the solidification process from being stopped. The task then sets the retry time back to the default. This feature keeps the CLI from hanging. Affected ProductsLanguages:This article is available in the following languages: |
|