Issue:
Why do Client Security and Server Security host devices send the following alert to the Policy Manager Consoler Alerts tab?
Access to file was blocked.
Application path: C:Example\Example.exe
Path: C:\ProgramData\Example\Example\
Resolution:
This type of block is the function of the Tamper Protection functionality. The alerts you are seeing are expected behaviour and not a cause for alarm.
Tamper protection functionality sees that some process tries to open a protected file with write access rights. Tamper protection blocks this operation, so the application gets ACCESS_DENIED error. Importantly, this block does not affect the normal operation of either third party application or Client Security itself, it is a cosmetic alert.
To stop the flood of alerts without reducing your protection level, you can create an alert sending exclusion in Policy Manager Console for that specific alert type:
- Log in to Policy Manager Console
- Select a host or policy domain from the Domain Tree
- Go to the Settings tab
- Go to the Alert sending page
- Scroll down to the Alert sending exclusions list and click Add
- Select Source as Tamper protection
- Select the Type, Action and Alert shown in the security event
- Click OK to finish adding rule
- Distribute policy (Ctrl + D)
Article no: 000009911