SYSTEM network traffic is allowed via "Allow McAfee signed applications" rule
Last Modified: 2021-04-01 07:47:53 Etc/GMT
Affected Products
Languages:
This article is available in the following languages:
Trellix CEO, Bryan Palma, explains the critical need for security that’s always learning.
As per Gartner, "XDR is an emerging technology that can offer improved threat prevention, detection and response."
Trellix announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.
Trellix Advanced Research Center analyzes threat data on ransomware, nation-states, sectors, vectors, LotL, MITRE ATT&CK techniques, and emails.
After December 1, 2024, please log in to the Thrive Portal for support, knowledge articles, tools, and downloads. For information about using the Thrive Portal, view the Trellix Thrive Portal User Guide.
SYSTEM network traffic is allowed via "Allow McAfee signed applications" rule
Technical Articles ID:
KB92248
Last Modified: 2021-04-01 07:47:53 Etc/GMT Environment
McAfee Endpoint Security (ENS) Firewall 10.7.0
Problem
After you install or upgrade to ENS 10.7.0, network traffic via the SYSTEM process is allowed by a McAfee core networking rule named "Allow McAfee signed applications." This fact affects SYSTEM-based network traffic, such as NetBIOS and SMB (for example, port 137, 138, and 445). The ENS Firewall processes firewall rules from a top-to-bottom order and "Allow McAfee signed applications" is toward the top of this list. If you created firewall rules to allow or block this type of SYSTEM-based network traffic, they do not apply. The reason is because the "Allow McAfee signed applications" firewall rule is processed before any other firewall rules. Example of related SYSTEM network traffic: Event: Traffic IP Address: x.x.x.x Description: SYSTEM Path: System Message: Allowed Outgoing UDP - Source x.x.x.x : netbios_dgm (138) Destination x.x.x.x : netbios_dgm (138) Matched Rule: Allow McAfee signed applications Time: 12/02/2019 11:22:55 AM Event: Traffic IP Address: x.x.x.x Description: SYSTEM Path: System Message: Allowed Incoming UDP - Source x.x.x.x : netbios_ns (137) Destination x.x.x.x : netbios_ns (137) Matched Rule: Allow McAfee signed applications Time: 12/02/2019 11:25:41 AM Event: Traffic IP Address: x.x.x.x Description: SYSTEM Path: System Message: Allowed Outgoing TCP - Source x.x.x.x : (49704) Destination x.x.x.x : msds (445) Matched Rule: Allow McAfee signed applications Cause
This issue is caused by "Allow McAfee signed applications" including a new Validation Trust Protection (VTP) Trust feature. The feature includes the network traffic associated with the SYSTEM process.
Solution
This issue is resolved in ENS 10.7.0 February 2020 Update. Our product software, upgrades, maintenance releases, and documentation are available on the Product Downloads site.
NOTE: You need a valid Grant Number for access. See KB56057 - How to download product updates and documentation for more information about the Product Downloads site, and alternate locations for some products. Workaround
There is no workaround. Disabling the McAfee core networking rules feature does not disable "Allow McAfee signed applications". This behavior is by design.
Related InformationAffected ProductsLanguages:This article is available in the following languages: |
|