<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Speed up Threat Emulation or ignore specific file in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Speed-up-Threat-Emulation-or-ignore-specific-file/m-p/97774#M2651</link>
    <description>&lt;P&gt;Many thanks Sigbjorn. What white list are you referring to, I can't see anywhere within Threat Extraction to add MD5 check sum?&lt;/P&gt;&lt;P&gt;I can only see two places where files can be excluded.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Inspect all domains and files except Trusted Sites&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;Prevent legitimate applications exploitation attempts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"1. Inspect all domains and files except Trusted Sites" I can see the domain could be added so that could be an option for trusted sites, there is also an option to add SHA1 HASH. Would adding a file here exclude Web Download Emulation ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;"2.&amp;nbsp;Prevent legitimate applications exploitation attempts"&amp;nbsp; I can see a process can be added but only as process path. Would adding file as *\&lt;SPAN&gt;Support-LogMeInRescue.exe exclude Web Download Emulation ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 09:03:10 GMT</pubDate>
    <dc:creator>64Bit</dc:creator>
    <dc:date>2020-09-29T09:03:10Z</dc:date>
    <item>
      <title>Speed up Threat Emulation or ignore specific file</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Speed-up-Threat-Emulation-or-ignore-specific-file/m-p/97002#M2621</link>
      <description>&lt;P&gt;We are finding a significant delay in downloading a specific .exe application (Support-LogMeInRescue.exe).&amp;nbsp; Threat emulation is set to Default (Emulate with Suspend) for .exe downloads which is ideal setting for these types of web downloads.&lt;/P&gt;&lt;P&gt;Is there any way to speed up Threat Emulation for&amp;nbsp;Support-LogMeInRescue.exe or to add this file to an exclusion from&amp;nbsp;Threat Emulation ?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 10:18:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Speed-up-Threat-Emulation-or-ignore-specific-file/m-p/97002#M2621</guid>
      <dc:creator>64Bit</dc:creator>
      <dc:date>2020-09-18T10:18:42Z</dc:date>
    </item>
    <item>
      <title>Re: Speed up Threat Emulation or ignore specific file</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Speed-up-Threat-Emulation-or-ignore-specific-file/m-p/97008#M2623</link>
      <description>&lt;P&gt;You can add the MD5 sum of the file to the Whitelist and override the inspection settings for it.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Sep 2020 11:37:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Speed-up-Threat-Emulation-or-ignore-specific-file/m-p/97008#M2623</guid>
      <dc:creator>Sigbjorn</dc:creator>
      <dc:date>2020-09-18T11:37:07Z</dc:date>
    </item>
    <item>
      <title>Re: Speed up Threat Emulation or ignore specific file</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Speed-up-Threat-Emulation-or-ignore-specific-file/m-p/97774#M2651</link>
      <description>&lt;P&gt;Many thanks Sigbjorn. What white list are you referring to, I can't see anywhere within Threat Extraction to add MD5 check sum?&lt;/P&gt;&lt;P&gt;I can only see two places where files can be excluded.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; Inspect all domains and files except Trusted Sites&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;Prevent legitimate applications exploitation attempts&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"1. Inspect all domains and files except Trusted Sites" I can see the domain could be added so that could be an option for trusted sites, there is also an option to add SHA1 HASH. Would adding a file here exclude Web Download Emulation ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;"2.&amp;nbsp;Prevent legitimate applications exploitation attempts"&amp;nbsp; I can see a process can be added but only as process path. Would adding file as *\&lt;SPAN&gt;Support-LogMeInRescue.exe exclude Web Download Emulation ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 09:03:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Speed-up-Threat-Emulation-or-ignore-specific-file/m-p/97774#M2651</guid>
      <dc:creator>64Bit</dc:creator>
      <dc:date>2020-09-29T09:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: Speed up Threat Emulation or ignore specific file</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Speed-up-Threat-Emulation-or-ignore-specific-file/m-p/97973#M2654</link>
      <description>&lt;P&gt;When you're in the Threat Policy view, there's view called "Whitelist Files" under the Threat Tools in the botton left corner. In that view you can add filenames with their md5sum, and then use that in the threat policy.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="image.png" style="width: 449px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8230i4BA9A5981E062327/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Once the file is added, go back to the Threat Policy and create a new exception, choose the file you created in the "Protection/Site/File/Blade" column.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Oct 2020 05:32:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Speed-up-Threat-Emulation-or-ignore-specific-file/m-p/97973#M2654</guid>
      <dc:creator>Sigbjorn</dc:creator>
      <dc:date>2020-10-01T05:32:22Z</dc:date>
    </item>
  </channel>
</rss>

