Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
neronidis
Explorer

Harmony Endpoint Behavioral Guard stops certutil.exe

Hello all,

after we have install the DHS Approved version (88.50) we are receiving very often the messages that certutil.exe was stopped by the behavioral guard. Thankfully the process is just stopped and not deleted or smth. As you already know this is a very important windows binary that can also be used for malicious purposes (LOTL attacks). So far we have identified that it is definately a false positive. The certutil is used by a local agent that uses the certutil.exe in order to check the Hash value of the packets that it receives from a server. 

Is anyone other in this forum facing the same issues? 

Adding an exlusion on the behavioral guard is possible but unfortunately the filtering options are limited. The distinguish between malicious and legit usage of the binary can be done only by filtering the command's arguments. Which is unfortunately not possible with the "add exclusion" option...

 

0 Kudos
6 Replies
PhoneBoy
Admin
Admin

I've seen a couple of TAC cases where this was specifically mentioned, but did not see any specific instructions.
I assume it depends on what exactly is triggering certutil.

0 Kudos
neronidis
Explorer

Well, the agent that trigers this behavior is the Forescout NAC agent. So yes it is a very legit application. The certutil is also called with the "-hashfile" argument. This means NO danger. It is being used for verification purposes. This should be clear to the Devs Team.

I expected more logic behind the behavioral guard.

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Open a SR# with TAC so they can look into this ! Usually, they will not use a competitors solution for their tests, and two endpoint solutions fighting against each other is not a standard use case...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
neronidis
Explorer

hello and thank you for the reply,

Forescout NAC agent is not a competing endpoint solution. In addition to that, the two of them have coexisted (not integrated! yes there is this option, too) on our endpoints for a long long time. 

I came here once again for some quick knowledge since opening a ticket is a long and painful process.

Have a nice day.

 

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Forescout NAC is a completly different approach, and CP SW will not do ACL or control network hardware - but regarding EP compliance and security, they partly are competing, and i think that is the reason for your issue...

Opening a CP Ticket is usually not long and painfull.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
PhoneBoy
Admin
Admin

Not sure this is a competitor exactly.
In any case, because it’s a false positive, a TAC case is the correct avenue to get this resolved.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events