Enabling and disabling exploit prevention

Prev Next

If Exploit Guard is enabled, you can use the Web UI or the API to enable and disable exploit prevention for all your host endpoints or for specific host sets in your environment. This section covers how to use the Web UI to enable and disable exploit prevention options for the xAgent default policy and a custom policy. See the Endpoint Security (HX) xAgent API Guide for more information on managing xAgent policies using the API.

This section covers the following topics:

Enabling exploit prevention
To enable exploit prevention for the xAgent default policy:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the Agent Default Policy link to access the Edit Policy page.

  4. Select the Exploit Guard Protection tab.

  5. Verify that the Exploit Guard switch is ON.

    Policy_ExGP_Switch_ON.png
  6. Select at least one of the following options, depending on your system requirements.

    Exploit prevention occurs if either of these options is selected.

    Important

    Enabling exploit prevention may result in data loss when an exploit is blocked in an active process and exploit prevention terminates the process that started the infection.

  7. Click Save.

To enable exploit prevention for a custom policy:

Note

See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the Agent Default Policy link to access the Edit Policy page.

  4. Select the Exploit Guard Protection tab.

  5. Verify that the Exploit Guard switch is ON.

    Policy_ExGP_Switch_ON.png
  6. Select at least one of the following options, depending on your system requirements.

    Exploit prevention occurs if either of these options is selected.

    Important

    Enabling exploit prevention may result in data loss when an exploit is blocked in an active process and exploit prevention terminates the process that started the infection.

  7. Click Save.

Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.

Disabling exploit Prevention
To disable exploit prevention for the xAgent default policy:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link to go to the Edit Policies page.

  4. Select the Exploit Guard Protection tab.

  5. Verify that the Exploit Guard switch is ON to ensure exploit detection is still enabled.

    Policy_ExGP_Switch_ON.png
  6. Clear both of the following options.

    • Prevent known suspicious behaviors

    • Terminate the exploited process

    Exploit prevention does not occur if these options are not selected.

  7. Click Save.

To disable exploit prevention for a custom policy:

Note

When you disable a setting in a custom policy, the setting is disabled for all host sets assigned to the policy. If you want select host sets to keep the original setting, you must create a new custom policy with the setting enabled and assign it to the selected host sets. See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Exploit Guard Protection tab.

  5. Verify that the Exploit Guard switch is ON to ensure exploit detection is still enabled.

    Policy_ExGP_Switch_ON.png
  6. Clear both of the following options.

    • Prevent known suspicious behaviors

    • Terminate the exploited process

    Exploit prevention does not occur if these options are not selected.

  7. Click Save.

Blocking exploited processes

You can enable and disable the exploit prevention option that blocks exploits when they are detected in monitored applications. Modifying the xAgent default policy allows you to enable or disable this setting for all of your host endpoints. The applications are not terminated, but the exploit affecting them is blocked.

Enabling exploit blocking
To enable the option to block exploits for all host endpoints in the xAgent default policy:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link to access the Edit Policies page.

  4. Select the Exploit Guard Protection tab.

  5. In the Exploit Guard Options section, select Prevent known suspicious behaviors. When this option is selected, exploits are blocked when they are detected.

    Policy_ExG_Block.png
  6. Click Save.

To enable the option to block exploits for selected host sets in a custom policy:

Note

See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Exploit Guard Protection tab.

  5. In the Exploit Guard Options section, select Prevent known suspicious behaviors. When this option is selected, exploits are blocked when they are detected.

    Policy_ExG_Block.png
  6. Click Save.

Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.

Disabling exploit blocking
To disable the option to block exploits for all host endpoints:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page

  3. In the Policies table, click the Agent Default Policy link to access the Edit Policies page.

  4. Select the Exploit Guard Protection tab.

  5. Clear Prevent known suspicious behaviors. When this option is no longer selected, exploits are not blocked when they are detected.

  6. Click Save.

To disable the option to block exploits for selected host sets:

Note

When you disable a setting in a custom policy, the setting is disabled for all host sets assigned to the policy. If you want select host sets to keep the original setting, you must create a new custom policy with the setting enabled and assign it to the selected host sets. See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Exploit Guard Protection tab.

  5. Clear Prevent known suspicious behaviors. When this option is no longer selected, exploits are not blocked when they are detected.

  6. Click Save.

Terminating exploited processes

You can enable and disable the exploit prevention option using the Web UI or the API. This option terminates a monitored application when an exploit for the application has been detected.

This section covers how to enable and disable exploit termination using the Web UI. See Endpoint Security (HX) REST API Guide for more information on using the API to modify xAgent policies.

Enabling exploit termination
To enable the option to terminate exploited processes for all host endpoints in the xAgent default policy:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link to access the Edit Policy page.

  4. Select the Exploit Guard tab.

  5. In the Exploit Guard Options section, select Terminate the exploited process. When this option is selected, exploited processes are terminated when they are detected.

    Policy_ExG_Terminate.png
  6. To quarantine any blocked exploit documents and scripts from running on your host endpoint, you can also select Quarantine malicious artifacts.

  7. Click Save.

To enable the option to terminate exploited processes for all selected host endpoints in a custom policy:

Note

See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Exploit Guard tab.

  5. In the Exploit Guard Options section, select Terminate the exploited process. When this option is selected, exploited processes are terminated when they are detected.

    Policy_ExG_Terminate.png
  6. To quarantine any blocked exploit documents and scripts from running on your host endpoint, you can also select Quarantine malicious artifacts.

  7. Click Save.

Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.

Disabling exploit termination
To disable the option to terminate exploited processes for all host endpoints:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link to access the Edit Policy page.

  4. Select the Exploit Guard tab.

  5. Clear Terminate the exploited process. When this option is no longer selected, exploited processes are not terminated when they are detected.

  6. Click Save.

To disable the option to terminate exploited processes for selected host sets:

Note

When you disable a setting in a custom policy, the setting is disabled for all host sets assigned to the policy. If you want select host sets to keep the original setting, you must create a new custom policy with the setting enabled and assign it to the selected host sets. See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. Select the Exploit Guard tab.

  4. Clear Terminate the exploited process. When this option is no longer selected, exploited processes are not terminated when they are detected.

  5. Click Save.

Notifying users about exploit prevention actions

You can enable and disable the option to notify users when exploit prevention actions occur using the Web UI or the API. This section covers how to enable and disable exploit prevention actions for all host endpoints or select host endpoints.

When notification is enabled, a notification message appears when an exploit is blocked or a monitored application is terminated because of an exploit.

ExGNotificationMsg.png
Enabling exploit prevention notifications
To enable the option to notify users about exploit prevention actions for all host endpoints:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link to access the Edit Policy page.

  4. Select the Exploit Guard tab.

  5. Select Notify the user on the host when an exploit has been blocked. When this option is selected, users are notified when an exploit is blocked.

    Important

    Enabling exploit prevention may result in data loss when an exploit is blocked in an active process and exploit prevention terminates the process that started the infection.

  6. Click Save.

To enable the option to notify users about exploit prevention actions for selected host sets:

Note

See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Exploit Guard tab.

  5. Select Notify the user on the host when an exploit has been blocked. When this option is selected, users are notified when an exploit is blocked.

    Important

    Enabling exploit prevention may result in data loss when an exploit is blocked in an active process and exploit prevention terminates the process that started the infection.

  6. Click Save.

Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.

Disabling exploit prevention notifications
To disable the option to notify users about exploit prevention actions for all host endpoints:
  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link to access the Edit Policy page.

  4. Select the Exploit Guard tab.

  5. Clear Notify the user on the host when an exploit has been blocked. When this option is no longer selected, users are no longer notified when an exploit is blocked.

  6. Click Save.

To disable the option to notify users about exploit prevention actions for selected host sets:

Note

When you disable a setting in a custom policy, the setting is disabled for all host sets assigned to the policy. If you want select host sets to keep the original setting, you must create a new custom policy with the setting enabled and assign it to the selected host sets. See Creating a Custom Policy for more information about using the Web UI to create a custom policy.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. In the Policies table, click the link for the custom policy you want to modify.

  4. Select the Exploit Guard tab.

  5. Clear Notify the user on the host when an exploit has been blocked. When this option is no longer selected, users are no longer notified when an exploit is blocked.

  6. Click Save.