Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Mitja-S3NEXT
Collaborator
Jump to solution

Devolutions - Remote Desktop manager - reported as ransomeware - Harmony Endpoint - Behavioral Guide

This was alreasy sent to the emergency response e-mail

 

Incident: 6c157e2b-5e8a-4d1e-9a17-5d70e5f2ba2f
Status: Active
User: *******
Computer: *******
OS: Windows 10
Trigger: c:\windows\system32\rundll32.exe
Triggered by: Endpoint Behavioral Guard
Trigger Time: 12. 4. 2024, 08:54:24
Protection Name: behavioral.win.anonymousmemorype.a
Entry Point: ****-PC\**** was logged in. msiexec.exe created [remotedesktopmanager_x64.exe]

 

 

1 Solution

Accepted Solutions
Mitja-S3NEXT
Collaborator

Solution Description form CP TAC service request: Remote admin tools are considered PUA under Check Point's policies due to their capabilities, therefor this one is considered TP. If the customer trusts the use of this specific one internally and uses it safely he may create a local exception for this one. Exclusion suggestion provided

View solution in original post

0 Kudos
3 Replies
G_W_Albrecht
Legend Legend
Legend

Why not open SR# with CP TAC?

 

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Mitja-S3NEXT
Collaborator

Service Request: 6-0003913660 opened 👍

0 Kudos
Mitja-S3NEXT
Collaborator

Solution Description form CP TAC service request: Remote admin tools are considered PUA under Check Point's policies due to their capabilities, therefor this one is considered TP. If the customer trusts the use of this specific one internally and uses it safely he may create a local exception for this one. Exclusion suggestion provided

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events