SC: Run commands stop when policy enforcement occurs
Last Modified: 2024-01-31 08:45:43 Etc/GMT
Affected Products
Languages:
This article is available in the following languages:
Trellix CEO, Bryan Palma, explains the critical need for security that’s always learning.
As per Gartner, "XDR is an emerging technology that can offer improved threat prevention, detection and response."
Trellix announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.
Trellix Advanced Research Center analyzes threat data on ransomware, nation-states, sectors, vectors, LotL, MITRE ATT&CK techniques, and emails.
As of May 14, 2024, Knowledge Base (KB) articles will only be published and updated in our new Trellix Thrive Knowledge space.
Log in to the Thrive Portal using your OKTA credentials and start searching the new space. Legacy KB IDs are indexed and you will be able to find them easily just by typing the legacy KB ID.
SC: Run commands stop when policy enforcement occurs
Technical Articles ID:
KB91353
Last Modified: 2024-01-31 08:45:43 Etc/GMT Environment
Application and Change Control (ACC) 8.2.1.143, 8.0.2.228 and later
Problem
SC: Run commands stop if policy enforcement occurs while the task is running. For example, resolidifying a system through the SC: Run command Cause
In versions before 8.0.2.228, the command-line interface (CLI) enters a hung state waiting on a command to return a response to the IPC channel. All other commands aren't allowed to run during this time. ACC 8.0.2.228 and later include a feature that fails a command when the CLI has to wait longer than expected. Failing the command allows policy enforcement to be prioritized. In ePolicy Orchestrator (ePO), the Solution
Create an Application Control Client task (SC: Run command) using the following:
so config set MaplCommLostRestart=5 eu This task sets the retry time on the command to 0 during the solidification. This setting prevents the solidification process from being stopped. The task then sets the retry time back to the default. This feature keeps the CLI from hanging. Affected ProductsLanguages:This article is available in the following languages: |
|