-
NMap and EDR
Hello it is normal for a client protected with EDR to not signal and block that NMap has been used? Thank yoi
-
Issue with establishing a connection between scanning and reputation server
Hello, All client devices where the agents are installed, the malware protection status is showing as malfunctioning. Upon reviewing the status details, the issue appears to be related to the inability to establish a connection with the scanning and reputation server. To troubleshoot, we have taken the following steps:…
-
How to create Xfence Exclusions/Rules?
Hello, I hope you are doing well, as far as I can see Xfence is the equivalent to Dataguard in MacOS, but how can we create rules or exclusions to tune it to specific needs? I do not see any related fields in the Profile?
-
Is it always required to reboot a machine after an agent install?
Hello, is it always necessary to reboot a device after the agent installation? Or could the install complete successfully without needing to restart the device? Also, what I understand from the docs is that it could require a restart as it could not, so when does the agent installation require and when not and why? (my…
-
Could we isolate Linux hosts?
Hello, I wanted to try the isolation feature on a Linux machine, but apparently it doesn't allow me, so I want to know if the isolation feature is available on Linux as well or just on Windows machines. Thank you.
-
How can i delete some files based on their extensions ?
Hello, I'm currently testing Withsecure EDR with ransomware. The solution works well (my files are not altered), but the ransomware leaves an encrypted duplicate next to my file (files .psr, as shown in the screenshot below). I attempted to find a way to properly remove all the .psr files using the "Remediation" > "Delete…
-
Selected Exclusions for EDR - "Accepted behawior"
Please improove one option, becouse in first step "Accepted behawior " i can select only „all Devices” or „Affected devices” , there will be great to see option to select specific devices, becouse this specific behawior on IT department, or developer department users can run on his many devices, but now WithSecure…
-
WithSecure license expiration grace period?
Is there a grace period after a WithSecure EPP license expires, or does it simply just stop working?
-
EDR Reporting
Hello, I'm looking to see if Annual EDR reports are available. some customers ask us if it is possible to create a PDF annual report of BCDs and actions taken by EDR. I found the monthly report but no annual report. Are there plans to add it later? Regards,
-
How to install WithSecure EDR and EPP on Citrix Server ?
Hi ! I have a citrix catalogs with 9 servers which each one morning rebooting from the snapshot of golden image. How i needs to install WithSecure on the golden image ? I guess it's not just run the .exe file of WithSecure intall. Thank you for your help !
-
Looking for assistance in dealing with Games in BOYD devices triggering EDR Broad Context Detection
So I'm trying to figure out how other people are dealing with this situation, we have about 80% seasonal staff who all bring their own device. While they are with us, we provide WithSecure ep,edr, vm as well as office and other online tools. Because these devices are owned by the end user, we get so many alerts after hours…
-
Change existing EPP-installation inplace to include EDR with new EDR-Voucher key?
Since the installer is the same for EPP and EDR, can an already existing install of EPP be changed via a new Voucher-Code to also include the EDR features?
-
F-Secure Elements EDR Windows client sensor service change
New version of Windows EDR sensor released to production Feb 8th 2022 (version 2022.1.19), which will introduce enhanced self-protection features, results removal of 'fsatps.exe' process. Therefore any existing controls witch rely on the presence of this 'fsatps.exe' process will become in-effective once this update is…