<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AnyDesk - on compliant DH version in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230515#M9560</link>
    <description>&lt;P&gt;The certificate used to sign the application should be excluded from Forensics Monitoring.&lt;/P&gt;</description>
    <pubDate>Tue, 22 Oct 2024 21:24:27 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-10-22T21:24:27Z</dc:date>
    <item>
      <title>AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/228916#M9466</link>
      <description>&lt;P&gt;&lt;SPAN&gt;anydesk.exe&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;Suspicious Events:&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;User Execution: Malicious File: anydesk.exe; Subvert Trust Controls: Code Signing: anydesk.exe;&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;Incident Details:&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;&lt;DIV class=""&gt;anydesk.exe(ecae8b9c820ce255108f6050c26c37a1);&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&lt;SPAN&gt;Client verasion : 88.60.0087&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;Will there be (planned) global solution (is a support ticket on this case already open?, I assume that many users/customers are facing the same problem) or do we have to put exclusions on every tenant of our customers?&lt;/DIV&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 04 Oct 2024 06:50:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/228916#M9466</guid>
      <dc:creator>Mitja-S3NEXT</dc:creator>
      <dc:date>2024-10-04T06:50:40Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/228942#M9470</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Yes, same question here. Anydesk is blocked/deleted with E2 engine.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2024 15:02:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/228942#M9470</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2024-10-04T15:02:30Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/228959#M9471</link>
      <description>&lt;P&gt;What did TAC say?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2024 18:13:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/228959#M9471</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-10-04T18:13:14Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/228965#M9473</link>
      <description>&lt;P&gt;This is likely a false positive that should be reported to TAC.&lt;/P&gt;</description>
      <pubDate>Fri, 04 Oct 2024 20:04:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/228965#M9473</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-04T20:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230061#M9532</link>
      <description>&lt;P style="font-weight: 400;"&gt;To close the loop on this, it appears that AnyDesk is now treated as a Potentially Unwanted Application.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk182752" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk182752&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="font-weight: 400;"&gt;If AnyDesk is legitimately used in your environment, you will need to crate a local exception.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2024 17:35:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230061#M9532</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-17T17:35:57Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230504#M9554</link>
      <description>&lt;P&gt;Yep seeing same issue here..&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 20:42:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230504#M9554</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2024-10-22T20:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230505#M9555</link>
      <description>&lt;P&gt;How are we able to push this as an MSP to all tenants?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 20:43:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230505#M9555</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2024-10-22T20:43:19Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230507#M9556</link>
      <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/MSSP-View/MSSP_Global_Exclusions.htm?TocPath=Managed%20Security%20Service%20Providers%20%20(MSSP)%7CGlobal%20Exclusions%7C_____0#Global_Exclusions" target="_blank"&gt;https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-HEP/MSSP-View/MSSP_Global_Exclusions.htm?TocPath=Managed%20Security%20Service%20Providers%20%20(MSSP)%7CGlobal%20Exclusions%7C_____0#Global_Exclusions&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 20:48:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230507#M9556</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-22T20:48:23Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230508#M9557</link>
      <description>&lt;P&gt;apparantly i still dont have access to all tenant's "smart exclusions"&lt;BR /&gt;do you know how i can activate that part?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 20:50:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230508#M9557</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2024-10-22T20:50:37Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230511#M9558</link>
      <description>&lt;P&gt;And what happened to the previous categorization "Riskware" for this type of software? The Antimalware policy had the possibility of not detecting it. does this no longer apply to E2?&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-left" image-alt="image.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/28167i2B994C6428AD0CBE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 20:52:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230511#M9558</guid>
      <dc:creator>MikeB</dc:creator>
      <dc:date>2024-10-22T20:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230512#M9559</link>
      <description>&lt;P&gt;Im honestly unsure how checkpoint expect us to whitelist this&lt;/P&gt;
&lt;P&gt;Everytime i right click in the eventlogs to automatically add it to global exclusion it just created a exclusion with a SHA1 value..&lt;BR /&gt;it does this everytime(with a different value)&lt;BR /&gt;So that exclusion isnt worth much&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 21:01:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230512#M9559</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2024-10-22T21:01:20Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230515#M9560</link>
      <description>&lt;P&gt;The certificate used to sign the application should be excluded from Forensics Monitoring.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 21:24:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230515#M9560</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-22T21:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230516#M9561</link>
      <description>&lt;P&gt;The certificate used for signing?? That’s a new one for me. Is there any examples somewhere perhaps?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 21:26:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230516#M9561</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2024-10-22T21:26:32Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230518#M9563</link>
      <description>&lt;P&gt;Endpoint is not my strong suit &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;However, it appears this is where you set it for "legacy" exclusions (specifically for Forensics &amp;gt; Anti-Ransomware and Behavioral Guard):&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-Common-for-HEP-HB/Legacy-Exclusions.htm?tocpath=Configuring%20Endpoint%20Policy%7CConfiguring%20the%20Threat%20Prevention%20Policy%7CAdding%20Exclusions%20to%20Rules%7CLegacy%20Exclusions%7C_____2#Adding_Global_Exclusions_..29" target="_blank"&gt;https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Topics-Common-for-HEP-HB/Legacy-Exclusions.htm?tocpath=Configuring%20Endpoint%20Policy%7CConfiguring%20the%20Threat%20Prevention%20Policy%7CAdding%20Exclusions%20to%20Rules%7CLegacy%20Exclusions%7C_____2#Adding_Global_Exclusions_..29&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2024 21:47:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230518#M9563</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-22T21:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230539#M9564</link>
      <description>&lt;P&gt;Would you expect that can work?&lt;/P&gt;
&lt;P&gt;but how do i get the certificate when app is being blocked&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 06:46:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230539#M9564</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2024-10-23T06:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230567#M9565</link>
      <description>&lt;P&gt;Maybe a workaround, install anydesk and make an exception to the installed path "c:\Program files\AnyDesk......".&lt;BR /&gt;How do you install it when it is blocked? You can temporarly disable the protection with these settings on every client.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 12:06:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230567#M9565</guid>
      <dc:creator>Mitja-S3NEXT</dc:creator>
      <dc:date>2024-10-23T12:06:17Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230576#M9566</link>
      <description>&lt;P&gt;yep i can disable security features. But.. that seems really out of boundary that its should even be considered just because you wanna install some software. Check Point should have a feaseable solution to installation/whitelisting software without having to disable security feature before installing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;and if i need to "re-deploy" Anydesk to computer, i cant mass disable features on all endpoint og remotely re-enable again &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 12:36:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230576#M9566</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2024-10-23T12:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230580#M9567</link>
      <description>&lt;P&gt;According to the internal notes of the SK documenting AnyDesk as PUA, yes.&lt;BR /&gt;Suggest engaging with the TAC here.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 12:41:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230580#M9567</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-10-23T12:41:37Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230581#M9568</link>
      <description>&lt;P&gt;I totally agree with you, that was the reason why I started this post in the first place.&lt;BR /&gt;Since no one provided a global solution, we had to this workarounds &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;You can mass disable and reenable through Software Deployment- Policy - see screenshot&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 12:48:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230581#M9568</guid>
      <dc:creator>Mitja-S3NEXT</dc:creator>
      <dc:date>2024-10-23T12:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: AnyDesk - on compliant DH version</title>
      <link>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230612#M9569</link>
      <description>&lt;P&gt;auuuh that way of disabling &lt;span class="lia-unicode-emoji" title=":face_with_open_mouth:"&gt;😮&lt;/span&gt; . didnt that cause a lot of havoc ?&lt;/P&gt;
&lt;P&gt;that way is literally uninstalling blades &amp;amp; then re-installing them afterwards &lt;span class="lia-unicode-emoji" title=":face_with_open_mouth:"&gt;😮&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2024 15:01:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/AnyDesk-on-compliant-DH-version/m-p/230612#M9569</guid>
      <dc:creator>skandshus</dc:creator>
      <dc:date>2024-10-23T15:01:44Z</dc:date>
    </item>
  </channel>
</rss>

