<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Conflict between Check Point Endpoint Security and Cynet: Unable to Suppress Tamper Alerts in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Conflict-between-Check-Point-Endpoint-Security-and-Cynet-Unable/m-p/228738#M9454</link>
    <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I'm facing a challenging issue between Check Point Endpoint Security and Cynet on our network, and I'm hoping someone here might have some insights or solutions.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The Situation:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Exclusions Set: I've configured exclusions in both the Check Point and Cynet consoles for their respective XDR and antivirus components.&lt;/P&gt;&lt;P&gt;Persistent Alerts: Despite these exclusions, Cynet continues to generate anti-tamper alerts whenever Check Point's antivirus operates. This results in constant email notifications and alerts that are becoming quite disruptive.&lt;/P&gt;&lt;P&gt;Support Tickets: I've opened two tickets with Cynet and two with Check Point to resolve this, but the problem persists.&lt;/P&gt;&lt;P&gt;What We've Tried and Learned:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;From Cynet Support:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;They confirmed that anti-tamper alerts are treated as special alerts and cannot be silenced or excluded via allowlists.&lt;/P&gt;&lt;P&gt;Cynet cannot exclude an alert from the anti-tamper module, so the alerts and notifications will continue.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;From Check Point Support:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;They suggested upgrading the client and then uninstalling the Anti-Malware component of their E2 engine.&lt;/P&gt;&lt;P&gt;Check Point advises that their antivirus engine cannot run alongside third-party AV solutions and recommends disabling it to prevent triggering Cynet.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Our Attempts:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Allowlisting in Cynet: Created allowlist entries to prevent alerts regarding "attempt to terminate Cynet" from processes like Task Manager. Unfortunately, this didn't stop the alerts.&lt;/P&gt;&lt;P&gt;Communication with Both Supports: Both vendors seem to suggest that their products aren't fully compatible with third-party solutions in this context.&lt;/P&gt;&lt;P&gt;Exclusions in Check Point: Even after setting folder exclusions in Check Point, it seems to still scan those folders and attempts to interact with Cynet processes.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The Dilemma:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Cynet's Stance: Cannot silence anti-tamper alerts.&lt;/P&gt;&lt;P&gt;Check Point's Stance: Recommends disabling their antivirus component to avoid conflicts.&lt;/P&gt;&lt;P&gt;Our Goal: To have both security solutions running concurrently without constant false-positive alerts or having to disable essential components.&lt;/P&gt;&lt;P&gt;Questions&lt;/P&gt;&lt;P&gt;Has anyone experienced similar conflicts between Check Point Endpoint Security and Cynet?&lt;/P&gt;&lt;P&gt;Is there a way to configure either product to better coexist without disabling AV security features?&lt;/P&gt;&lt;P&gt;PS: Performance: We aren't experiencing performance issues or file access problems—it's primarily about the alerts.Versions: We're using up-to-date versions of both products where possible.Environment: The issue occurs across multiple tenants and client IDs within our organization.&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;</description>
    <pubDate>Wed, 02 Oct 2024 12:37:20 GMT</pubDate>
    <dc:creator>Cymone92</dc:creator>
    <dc:date>2024-10-02T12:37:20Z</dc:date>
    <item>
      <title>Conflict between Check Point Endpoint Security and Cynet: Unable to Suppress Tamper Alerts</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Conflict-between-Check-Point-Endpoint-Security-and-Cynet-Unable/m-p/228738#M9454</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;&lt;P&gt;I'm facing a challenging issue between Check Point Endpoint Security and Cynet on our network, and I'm hoping someone here might have some insights or solutions.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The Situation:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Exclusions Set: I've configured exclusions in both the Check Point and Cynet consoles for their respective XDR and antivirus components.&lt;/P&gt;&lt;P&gt;Persistent Alerts: Despite these exclusions, Cynet continues to generate anti-tamper alerts whenever Check Point's antivirus operates. This results in constant email notifications and alerts that are becoming quite disruptive.&lt;/P&gt;&lt;P&gt;Support Tickets: I've opened two tickets with Cynet and two with Check Point to resolve this, but the problem persists.&lt;/P&gt;&lt;P&gt;What We've Tried and Learned:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;From Cynet Support:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;They confirmed that anti-tamper alerts are treated as special alerts and cannot be silenced or excluded via allowlists.&lt;/P&gt;&lt;P&gt;Cynet cannot exclude an alert from the anti-tamper module, so the alerts and notifications will continue.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;From Check Point Support:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;They suggested upgrading the client and then uninstalling the Anti-Malware component of their E2 engine.&lt;/P&gt;&lt;P&gt;Check Point advises that their antivirus engine cannot run alongside third-party AV solutions and recommends disabling it to prevent triggering Cynet.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Our Attempts:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Allowlisting in Cynet: Created allowlist entries to prevent alerts regarding "attempt to terminate Cynet" from processes like Task Manager. Unfortunately, this didn't stop the alerts.&lt;/P&gt;&lt;P&gt;Communication with Both Supports: Both vendors seem to suggest that their products aren't fully compatible with third-party solutions in this context.&lt;/P&gt;&lt;P&gt;Exclusions in Check Point: Even after setting folder exclusions in Check Point, it seems to still scan those folders and attempts to interact with Cynet processes.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;The Dilemma:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Cynet's Stance: Cannot silence anti-tamper alerts.&lt;/P&gt;&lt;P&gt;Check Point's Stance: Recommends disabling their antivirus component to avoid conflicts.&lt;/P&gt;&lt;P&gt;Our Goal: To have both security solutions running concurrently without constant false-positive alerts or having to disable essential components.&lt;/P&gt;&lt;P&gt;Questions&lt;/P&gt;&lt;P&gt;Has anyone experienced similar conflicts between Check Point Endpoint Security and Cynet?&lt;/P&gt;&lt;P&gt;Is there a way to configure either product to better coexist without disabling AV security features?&lt;/P&gt;&lt;P&gt;PS: Performance: We aren't experiencing performance issues or file access problems—it's primarily about the alerts.Versions: We're using up-to-date versions of both products where possible.Environment: The issue occurs across multiple tenants and client IDs within our organization.&lt;/P&gt;&lt;P&gt;Thank you in advance&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 12:37:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Conflict-between-Check-Point-Endpoint-Security-and-Cynet-Unable/m-p/228738#M9454</guid>
      <dc:creator>Cymone92</dc:creator>
      <dc:date>2024-10-02T12:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: Conflict between Check Point Endpoint Security and Cynet: Unable to Suppress Tamper Alerts</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Conflict-between-Check-Point-Endpoint-Security-and-Cynet-Unable/m-p/228801#M9459</link>
      <description>&lt;P&gt;Knowing what versions of all components are used and exactly what you’ve tried to configure (with screenshots) might be helpful.&lt;/P&gt;
&lt;P&gt;Having said that, you have two products performing a similar task operating in the same privileged area of the OS kernel.&lt;BR /&gt;They also both have anti-tampering mechanisms in place to ensure malicious software doesn’t impact their ability to protect your systems.&lt;BR /&gt;Even if you manage to get this working, a change in either product might recreate the situation you’re trying to avoid (or worse).&lt;/P&gt;
&lt;P&gt;Which raises the question: what is the business reason driving this request?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Oct 2024 20:07:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Conflict-between-Check-Point-Endpoint-Security-and-Cynet-Unable/m-p/228801#M9459</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-02T20:07:30Z</dc:date>
    </item>
  </channel>
</rss>

