Excluded process triggers Data Execution Prevention signature 9990
Last Modified: 2022-04-27 02:05:11 Etc/GMT
Affected Products
Languages:
This article is available in the following languages:
Trellix CEO, Bryan Palma, explains the critical need for security that’s always learning.
As per Gartner, "XDR is an emerging technology that can offer improved threat prevention, detection and response."
Trellix announced the establishment of the Trellix Advanced Research Center to advance global threat intelligence.
Trellix Advanced Research Center analyzes threat data on ransomware, nation-states, sectors, vectors, LotL, MITRE ATT&CK techniques, and emails.
After December 1, 2024, please log in to the Thrive Portal for support, knowledge articles, tools, and downloads. For information about using the Thrive Portal, view the Trellix Thrive Portal User Guide.
Excluded process triggers Data Execution Prevention signature 9990
Technical Articles ID:
KB92944
Last Modified: 2022-04-27 02:05:11 Etc/GMT Environment
Endpoint Security (ENS) Threat Prevention 10.x Microsoft Data Execution Prevention (DEP) Problem
When you create an exclusion for a process for Exploit Prevention signature 9990, the application continues to trigger signature 9990.
Solution
This behavior is as designed. NOTE: Signature 9990 is grayed out in the Signature list. To enable or disable the signature, use the option "Enable Windows Data Execution Prevention" in the Windows Data Execution Prevention row of the policy. As such, the signature settings for signature 9990 must be both enabled or disabled for Block and Report. For more information, see the "Windows Data Execution Prevention (DEP)" section of the Endpoint Security Interface Reference Guide. To submit a new product idea, go to the Enterprise Customer Product Ideas page.
Click Sign In and enter your ServicePortal User ID and password. If you do not yet have a ServicePortal or Community account, click Register to register for a new account on either website. For more information about product ideas, see KB60021 - How to submit a Product Idea. Workaround
This workaround disables all ENS Buffer Overflow and Illegal API Use protection for the associated process.
Affected ProductsLanguages:This article is available in the following languages: |
|