I'm slowly migrating from Microsoft Defender to Check Point Harmony Endpoint.
Today I discovered that when Dell CommandUpdate attempts to suspend BitLocker before a BIOS update, Harmony Endpoint detects the action as ransomware (a false positive) and disrupts the event. For good measure, Playblocks then isolates the computer for 24 hours, but that is a downstream effect.
If I manually suspend Bitlocker through the Windows GUI, that action is allowed to proceed. It's when c:\windows\system32\wbem\wmiprvse.exe tries to do it that alarms go off.
Does anyone have a way to allow a trusted program like CommandUpdate to work with wmi?
Thanks,
Joe