Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
nwgy
Explorer

Exclusions on cmd.exe

We run a program called AutoIt that compiles scripts into .exe files. These files are often flagged as malware, and so in response we have added a file exclusion on cmd.exe that seems to have solved the problem. Will that exclusion then allow other sub-processes running off of cmd.exe to execute that may be nefarious?

If so, what is the best way to exclude these compiled scripts?

0 Kudos
6 Replies
PhoneBoy
Admin
Admin

Unfortunately, I assume other malicious things that run under cmd.exe will also be excluded.
Have you confirmed these scripts show when running in Task Manager are running under cmd.exe?

0 Kudos
nwgy
Explorer

When we didn't have the exclusion, the script (compiled) were blocked. With the exclusion, they run.

0 Kudos
lluner
Advisor

@nwgy 

It could show what the forensic blade is showing for us to try to make the exceptions ?

0 Kudos
nwgy
Explorer

I am not sure what you mean?

 

0 Kudos
lluner
Advisor

@nwgy 

I'm asking for the logs to try to identify the folder or file so I can do the deletion and not do the deletion by the executable cmd.exe

0 Kudos
PhoneBoy
Admin
Admin

And Forensics Blade should show you what the scripts are doing when they run.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events