Administrators need to be aware of any attempt to recover the CLI with an incorrect password. In case any attempt is made to breach security, the CLI needs to be disabled immediately to thwart the attempt.
You can configure Application Control and Change Control products to notify the administrator of any unsuccessful attempts to recover the CLI on the endpoint.
Note
This feature is available only in Trellix ePO - On-prem-managed configuration and unavailable in standalone configuration.
Task
- On the Trellix ePO - On-prem console, select Menu → Policy → Policy Catalog.
- Select Solidcore 8.x.x: General for the product.
- In the Configuration (Client) category, click Duplicate for the Trellix Default policy.
- Specify the policy name, then click OK.
- Open the policy and click the CLI tab.
-
Enable the feature by clicking
Enable.
By default, this feature is disabled.
-
Specify the number of failed attempts and the interval after which to disable the CLI in case of a security breach.
By default, the CLI is disabled if a user makes three unsuccessful attempts in 30 minutes.
-
Specify how long to disable the CLI if any user makes unsuccessful logon attempts.
By default the CLI is disabled for 30 minutes.
- Click Save.
- Apply the policy to the endpoints.
Results
- Each attempt to recover the CLI with the correct password generates the Recovered Local CLI event.
- Any attempt to recover the CLI with an incorrect password generates the Unable to Recover Local CLI event.
When the user exceeds the permitted number of failed attempts (as defined in the policy), the CLI recovery is disabled to prevent the breach attempt. The Disabled Local CLI Access event is generated. This is priority event and is sent immediately to the Trellix ePO - On-prem console.