Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
nwgy
Explorer

Exclusions on cmd.exe

We run a program called AutoIt that compiles scripts into .exe files. These files are often flagged as malware, and so in response we have added a file exclusion on cmd.exe that seems to have solved the problem. Will that exclusion then allow other sub-processes running off of cmd.exe to execute that may be nefarious?

If so, what is the best way to exclude these compiled scripts?

6 Replies
PhoneBoy
Admin
Admin

Unfortunately, I assume other malicious things that run under cmd.exe will also be excluded.
Have you confirmed these scripts show when running in Task Manager are running under cmd.exe?

nwgy
Explorer

When we didn't have the exclusion, the script (compiled) were blocked. With the exclusion, they run.

lluner
Advisor

@nwgy 

It could show what the forensic blade is showing for us to try to make the exceptions ?

nwgy
Explorer

I am not sure what you mean?

 

lluner
Advisor

@nwgy 

I'm asking for the logs to try to identify the folder or file so I can do the deletion and not do the deletion by the executable cmd.exe

PhoneBoy
Admin
Admin

And Forensics Blade should show you what the scripts are doing when they run.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events