<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can I create an exception for anti-ransomeware in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-I-create-an-exception-for-anti-ransomeware/m-p/36170#M13535</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you already try to use a whitelist for TP following Threat Prevention Administration Guide R80.20 p.110f ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 17 Oct 2018 14:11:53 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2018-10-17T14:11:53Z</dc:date>
    <item>
      <title>Can I create an exception for anti-ransomeware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-I-create-an-exception-for-anti-ransomeware/m-p/36169#M13534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good Morning.&amp;nbsp; We have a customer running one of the latest endpoint deployments.&amp;nbsp; The client is at 80.83.xxx.&amp;nbsp; Regular users have no problem, but developers have&amp;nbsp;problems when&amp;nbsp;they go to deploy code or do&amp;nbsp;"things" in Visual Studio. They are getting a false positive pop up from Anti-Ransomeware.&amp;nbsp; At times it freezes/crashes the VS app, other times it completes.&amp;nbsp; Every time though its causing help-desk calls and its getting visible.&amp;nbsp; Specifically c:/program files (x86)\microsoft visual studio 14.0\common7\ide\devenv.exe is the trigger.&amp;nbsp; Is there a way to eliminate or explicitly trust this executable?&amp;nbsp; There is another exe that I need to do as well which is vshub.exe.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for your time.&amp;nbsp; I'm attaching the overview for your reference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2018 13:21:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-I-create-an-exception-for-anti-ransomeware/m-p/36169#M13534</guid>
      <dc:creator>Paul_Warnagiris</dc:creator>
      <dc:date>2018-10-17T13:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: Can I create an exception for anti-ransomeware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-I-create-an-exception-for-anti-ransomeware/m-p/36170#M13535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you already try to use a whitelist for TP following Threat Prevention Administration Guide R80.20 p.110f ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2018 14:11:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-I-create-an-exception-for-anti-ransomeware/m-p/36170#M13535</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-10-17T14:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: Can I create an exception for anti-ransomeware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-I-create-an-exception-for-anti-ransomeware/m-p/36171#M13536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did not because my question is geared towards endpoint management, not firewall or network management.&amp;nbsp; Your guide is talking about gateway management unless I'm mistaking.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2018 15:11:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-I-create-an-exception-for-anti-ransomeware/m-p/36171#M13536</guid>
      <dc:creator>Paul_Warnagiris</dc:creator>
      <dc:date>2018-10-17T15:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: Can I create an exception for anti-ransomeware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-I-create-an-exception-for-anti-ransomeware/m-p/36172#M13537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class=""&gt;Hi Paul&lt;/P&gt;&lt;P class=""&gt;We made a rule that excluded the path to the development.&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;We got a rpa server calling powershell scripts and everytime it was called the anti-ransomware blade triggered and deleted the script.&lt;/P&gt;&lt;P class=""&gt;So we were recommended to create a rule in the endpoint mgmt server that would bypass the path to the script for the given server.&lt;/P&gt;&lt;P class=""&gt;So create a rule which include your development server and bypass the Application and it working directory.&lt;/P&gt;&lt;P class=""&gt;You might also do this for the folders were you compile codes into executeble files.&lt;/P&gt;&lt;P class=""&gt;&lt;/P&gt;&lt;P class=""&gt;By the way. Latest stable version is e80.87 but as I recall there shouldnt be any difference between the versions in regards to handling the issue you are mention in your question.&lt;/P&gt;&lt;P class=""&gt;&lt;/P&gt;&lt;P class=""&gt;Hope this would help&lt;/P&gt;&lt;P class=""&gt;&lt;/P&gt;&lt;P class=""&gt;Best regards&lt;/P&gt;&lt;P class=""&gt;Kim&lt;/P&gt;&lt;P class=""&gt;&lt;/P&gt;&lt;P class=""&gt;example of exclude folder/file on the antiransomeware blade for the endpoint.&lt;/P&gt;&lt;P class=""&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/71635_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2018 18:36:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-I-create-an-exception-for-anti-ransomeware/m-p/36172#M13537</guid>
      <dc:creator>Kim_Moberg</dc:creator>
      <dc:date>2018-10-17T18:36:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can I create an exception for anti-ransomeware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-I-create-an-exception-for-anti-ransomeware/m-p/36173#M13538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is true - for Endpoint Server, the procedure is given in e.g. Endpoint Security Administration Guide R77.30.03 Management Server p.182:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To configure trusted processes:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;1. In the &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Properties &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;of the &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Scan all files on Access &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;Action, click &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Add&lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;2. In the &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Trusted Processes &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;window, enter the fully qualified path or an environment variable for the trusted executable file. For example: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;• &lt;/SPAN&gt;&lt;SPAN style="font-size: medium; font-family: Courier New,Courier New;"&gt;C:\Program Files\MyTrustedDirectory\MyTrustedProgram.exe &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;• %programdata%\MyTrustedProgram.exe&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;3. Click &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;OK&lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;The trusted program shows in the &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Trusted Processes &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;list. &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2018 08:22:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-I-create-an-exception-for-anti-ransomeware/m-p/36173#M13538</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-10-18T08:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: Can I create an exception for anti-ransomeware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-I-create-an-exception-for-anti-ransomeware/m-p/36174#M13539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P class="" style="color: #333333; background-color: inherit; font-weight: 300; text-decoration: none; margin: 0.5cm 0cm 3pt; padding: 15px 0pt 0pt;"&gt;To exclude a process from monitoring:&lt;/P&gt;&lt;OL class="" style="color: #333333; margin-top: 6pt; margin-bottom: 0pt;"&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 6pt 0pt 0pt; padding: 0pt;"&gt;From a SandBlast Agent Forensics and Anti-Ransomware rule in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;Policy&lt;/STRONG&gt;, right-click the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;Monitoring and Exclusions&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;action and select&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;Edit Shared Action&lt;/STRONG&gt;&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 6pt 0pt 0pt; padding: 0pt;"&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;Add exclusion&lt;/STRONG&gt;&lt;/STRONG&gt;.&lt;/LI&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 6pt 0pt 0pt; padding: 0pt;"&gt;In the window that opens select:&lt;UL class="" style="margin-top: 3pt; margin-bottom: 0pt;"&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;Process&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- To exclude an executable. You can also include Certificate information.&lt;UL class="" style="margin-top: 3pt; margin-bottom: 0pt;"&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;In&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;Process name&lt;/STRONG&gt;&lt;/STRONG&gt;, enter the name of the executable.&lt;/LI&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;Optional: Enter more information in the fields shown&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;Signer&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is the company that signs the certificate. The more information you enter, the more specified the exclusion will be.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;Certificate&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;- To exclude processes based on the company that signs the certificate, for example, Google.&lt;UL class="" style="margin-top: 3pt; margin-bottom: 0pt;"&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 3pt 0pt 0pt; padding: 0pt;"&gt;In&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;Certificate Data&lt;/STRONG&gt;&lt;/STRONG&gt;, enter a name of company that signs certificates, or browse to add a certificate file.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 6pt 0pt 0pt; padding: 0pt;"&gt;Click&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;&lt;STRONG class="" style="color: inherit; background-color: inherit; font-weight: bold; padding: 0pt;"&gt;OK.&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI class="" style="color: #000000; background-color: inherit; font-weight: normal; text-decoration: none; text-indent: 0cm; margin: 6pt 0pt 0pt; padding: 0pt;"&gt;The exclusion is added to the Exclusions list.&lt;/LI&gt;&lt;/OL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Oct 2018 15:52:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-I-create-an-exception-for-anti-ransomeware/m-p/36174#M13539</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-10-19T15:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: Can I create an exception for anti-ransomeware</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-I-create-an-exception-for-anti-ransomeware/m-p/36175#M13540</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Awesome Dameon.&amp;nbsp; Thanks much!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Oct 2018 07:45:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Can-I-create-an-exception-for-anti-ransomeware/m-p/36175#M13540</guid>
      <dc:creator>Paul_Warnagiris</dc:creator>
      <dc:date>2018-10-22T07:45:05Z</dc:date>
    </item>
  </channel>
</rss>

