Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Bac26
Contributor

Stop endpoint proccess

Hello

do you know any way to stop endpoint process? like anti-malware, forensics . Passdialog seems not working anymore and create a policy with no blade installed dont seems nice solution

 

Thank you

0 Kudos
22 Replies
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

What is the objective of stopping the 'processes' in this context?

CCSM R77/R80/ELITE
0 Kudos
Bac26
Contributor

Hello Chris

For troubleshooting purpose or it happened got stuck some processes and neeeded reboot machine but when is a server not nice

Br

 

 

 

 

0 Kudos
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

Which version of endpoint client are you currently using and where from / how long ago did you obtain passdialog ?

CCSM R77/R80/ELITE
0 Kudos
Bac26
Contributor

Version 87.00 and got from support but don't work so try see if other way to stop services

0 Kudos
Chris_Atkinson
MVP Gold CHKP MVP Gold CHKP
MVP Gold CHKP

@jcortez Are you aware of any issues with passdialog and E87.x?

CCSM R77/R80/ELITE
0 Kudos
jcortez
MVP Silver CHKP MVP Silver CHKP
MVP Silver CHKP

@Chris_Atkinson 

There would be an issue if the older PassDialog.exe tool was being used. I order to use the correct version of PassDialog.exe, you would need to trigger the uninstall of our client and then cancel out the uninstall once you get the password prompt.

 

You would then need to navigate to C:\Users\<your user name>\AppData\Local\Temp\ and then search for PassDialog.exe. For example, this is where mine was created:

C:\Users\jcortez\AppData\Local\Temp\{30921FC7-785C-4B11-9390-840B403E39DA}\

 

 

We no longer provide the PassDialog.exe and Hash.exe tools from support since R&D made it available when triggering the endpoint client uninstall. If a PassDialog.exe tool was provided to the customer, it will not work. Each is version specific AFAIK.


Justin Cortez
Technology Leader | Endpoint Cyber Security Products | Americas Endpoint Team
the_rock
MVP Gold
MVP Gold

Since old SBA (aka harmony endpoint now) is EDR solution, I believe it can only be stopped/termniated from the portal itself. Do you see any options from the portal or endpoint dashboard to stop it?

Andy

Best,
Andy
0 Kudos
Bac26
Contributor

Nothing from portal neither from endpoint dashboard 

0 Kudos
the_rock
MVP Gold
MVP Gold

Are you managing this with cloud portal or on prem endpoint server?

Andy

Best,
Andy
0 Kudos
Bac26
Contributor

on premises...

0 Kudos
the_rock
MVP Gold
MVP Gold

Hey @Bac26 , just curious, were you able to sort this out?

Hope you contacted TAC if you haven't already.

Cheers mate.

Andy

Best,
Andy
0 Kudos
Bac26
Contributor

no they closed my ticket because after reboot the services restarted, but this is not the way

0 Kudos
the_rock
MVP Gold
MVP Gold

You mean reboot of that particular endpoint?

Best,
Andy
0 Kudos
Bac26
Contributor

exactly

0 Kudos
the_rock
MVP Gold
MVP Gold

K, so sounds like specific process was stuck. Not sure if there is anything TAC could give you after the fact...

Best,
Andy
0 Kudos
Bac26
Contributor

i just need a procedure to stop single process without rebooting in this case a server.

0 Kudos
the_rock
MVP Gold
MVP Gold

The only 2 logical ways I can think of would be either via task manager on the PC itself or via endpoint dashboard, but maybe someone else can confirm for you.

Best,
Andy
0 Kudos
Bac26
Contributor

both already checked not possible..

0 Kudos
Valerio5286
Participant

Hi @Bac26.

Do you have any solution?
I have the same problem.
Regards.

0 Kudos
AdiGH
Employee
Employee

You can use Push Op -- > Agent Settings --> Kill process 

0 Kudos
JonnyRabinowitz
Employee
Employee

There is an option to disable capabilities on a client. This can be set from the Client Settings Policy. This was also enhanced in client release E88.30 to add "Password Protection" and a "Timeout"; an interval after which the capabilities are restored. These additional configuration items are available in cloud management. I am not sure whether these additional settings are available on premise

When capabilities are "disabled" I am not sure what happens under the covers and whether the relevant processes are stopped - I will try and check/ In any case may be worth trying

I also refer to the "Harmony Endpoint Packing a Punch Webinar" 

https://community.checkpoint.com/t5/Endpoint/Harmony-Endpoint-Packing-a-Punch-Video-Slides-and-Q-amp...

where some of these capabilities were discussed

0 Kudos
Firewall_Head
Explorer

Hi @JonnyRabinowitz ,

One of my customer's has recently received an alert for the anti-ransomware blade error, is there a way to restart only the service that is taking care of the anti-ransomware function because rebooting the server is not an option for us.

Is anything possible with the Passdiag.exe that comes with the agent package?

Thanks in advance!
=====

WR,

FH

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events