<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Harmony Endpoint Behavioral Guard stops certutil.exe in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Behavioral-Guard-stops-certutil-exe/m-p/226234#M9300</link>
    <description>&lt;P&gt;hello and thank you for the reply,&lt;/P&gt;&lt;P&gt;Forescout NAC agent is &lt;STRONG&gt;not&lt;/STRONG&gt; a competing endpoint solution.&amp;nbsp;In addition to that, the two of them have coexisted (not integrated! yes there is this option, too) on our endpoints for a long long time.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I came here once again for some quick knowledge since opening a ticket is a long and painful process.&lt;/P&gt;&lt;P&gt;Have a nice day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 11 Sep 2024 08:31:23 GMT</pubDate>
    <dc:creator>neronidis</dc:creator>
    <dc:date>2024-09-11T08:31:23Z</dc:date>
    <item>
      <title>Harmony Endpoint Behavioral Guard stops certutil.exe</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Behavioral-Guard-stops-certutil-exe/m-p/226144#M9288</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;after we have install the DHS Approved version (88.50) we are receiving very often the messages that certutil.exe was stopped by the behavioral guard. &lt;STRONG&gt;Thankfully&lt;/STRONG&gt; the process is just stopped and not deleted or smth. As you already know this is a very important windows binary that can also be used for malicious purposes (LOTL attacks). So far we have identified that it is definately a false positive. The certutil is used by a local agent that uses the certutil.exe in order to check the Hash value of the packets that it receives from a server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is anyone other in this forum facing the same issues?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Adding an exlusion on the behavioral guard is possible but unfortunately the filtering options are limited. The distinguish between malicious and legit usage of the binary can be done only by filtering the command's arguments. Which is unfortunately not possible with the "add exclusion" option...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 13:25:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Behavioral-Guard-stops-certutil-exe/m-p/226144#M9288</guid>
      <dc:creator>neronidis</dc:creator>
      <dc:date>2024-09-10T13:25:14Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Endpoint Behavioral Guard stops certutil.exe</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Behavioral-Guard-stops-certutil-exe/m-p/226170#M9292</link>
      <description>&lt;P&gt;I've seen a couple of TAC cases where this was specifically mentioned, but did not see any specific instructions.&lt;BR /&gt;I assume it depends on what exactly is triggering certutil.&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 17:00:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Behavioral-Guard-stops-certutil-exe/m-p/226170#M9292</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-10T17:00:16Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Endpoint Behavioral Guard stops certutil.exe</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Behavioral-Guard-stops-certutil-exe/m-p/226221#M9295</link>
      <description>&lt;P&gt;Well, the agent that trigers this behavior is the Forescout NAC agent. So yes it is a very legit application. The certutil is also called with the "&lt;SPAN&gt;-hashfile" argument. This means NO danger. It is being used for verification purposes. This should be clear to the Devs Team.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I expected more logic behind the behavioral guard.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 06:19:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Behavioral-Guard-stops-certutil-exe/m-p/226221#M9295</guid>
      <dc:creator>neronidis</dc:creator>
      <dc:date>2024-09-11T06:19:52Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Endpoint Behavioral Guard stops certutil.exe</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Behavioral-Guard-stops-certutil-exe/m-p/226232#M9298</link>
      <description>&lt;P&gt;Open a SR# with TAC so they can look into this ! Usually, they will not use a competitors solution for their tests, and two endpoint solutions fighting against each other is not a standard use case...&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 08:10:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Behavioral-Guard-stops-certutil-exe/m-p/226232#M9298</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-09-11T08:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Endpoint Behavioral Guard stops certutil.exe</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Behavioral-Guard-stops-certutil-exe/m-p/226234#M9300</link>
      <description>&lt;P&gt;hello and thank you for the reply,&lt;/P&gt;&lt;P&gt;Forescout NAC agent is &lt;STRONG&gt;not&lt;/STRONG&gt; a competing endpoint solution.&amp;nbsp;In addition to that, the two of them have coexisted (not integrated! yes there is this option, too) on our endpoints for a long long time.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I came here once again for some quick knowledge since opening a ticket is a long and painful process.&lt;/P&gt;&lt;P&gt;Have a nice day.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 08:31:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Behavioral-Guard-stops-certutil-exe/m-p/226234#M9300</guid>
      <dc:creator>neronidis</dc:creator>
      <dc:date>2024-09-11T08:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Endpoint Behavioral Guard stops certutil.exe</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Behavioral-Guard-stops-certutil-exe/m-p/226240#M9305</link>
      <description>&lt;P&gt;Forescout NAC is a completly different approach, and CP SW will not do ACL or control network hardware - but regarding EP compliance and security, they partly are competing, and i think that is the reason for your issue...&lt;/P&gt;
&lt;P&gt;Opening a CP Ticket is usually not long and painfull.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 09:22:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Behavioral-Guard-stops-certutil-exe/m-p/226240#M9305</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2024-09-11T09:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: Harmony Endpoint Behavioral Guard stops certutil.exe</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Behavioral-Guard-stops-certutil-exe/m-p/226263#M9310</link>
      <description>&lt;P&gt;Not sure this is a competitor exactly.&lt;BR /&gt;In any case, because it’s a false positive, a TAC case is the correct avenue to get this resolved.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 12:46:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Behavioral-Guard-stops-certutil-exe/m-p/226263#M9310</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-11T12:46:50Z</dc:date>
    </item>
  </channel>
</rss>

