Events: Create Custom Policy page

Prev Next

Define custom rules for the executable file associated with the event. This option is available only for the Execution Denied, ActiveX Installation Prevented, File Write Denied, Installation Denied, Process Hijack Attempted, VASR Violation Detected, and Nx Violation Detected events. By default, the recommended rule tab is highlighted. If needed, you can add rules from other tabs.

This page is displayed when you:

  • Click Create Policy action on the Solidcore Events page.

  • Select an event and click Create Policy on the Events Details page.

Option definitions

Option

Definition

Event Details

Lists relevant details for the selected file.

  • Event Display Name — Displays the event name that appears on the ePO - On-prem console.

  • Deny Reason — Displays the reason why the execution was denied at the endpoint for Execution Denied events.

  • Parent Process Name — Displays the path to the parent process for the process associated with the file that tried to execute or make changes for which the event is generated.

  • Process Name — Displays the path to the process associated with the file that tried to execute or make changes for which the event is generated. Also, for File Write Denied events, clicking Lookup in TIE opens the TIE Reputations page that allows you to view or change the file reputation.

  • File Name — Displays the name of the selected file. Also, clicking Lookup in TIE opens the TIE Reputations page that allows you to view or edit the file reputation.

  • Final Reputation — Displays the final reputation for the selected file. The color that the reputation is displayed in indicates whether the file is trusted, malicious, or unknown.

Color

Reputation

Green

Known Trusted

Most Likely Trusted

Might be Trusted

Orange

Unknown

Red

Might be Malicious

Most Likely Malicious

Known Malicious

  • Reputation (at Time of Execution) — This value is not applicable on this page. This is because the Reputation (at Time of Execution) value is only applicable for the Execution Denied events where execution is denied due to malicious reputation.

  • Reputation Source — Indicates the reputation source. Possible values are TIE and GTI.

  • Certificate — Displays the name of the certificate vendor. The color that the vendor is displayed in indicates whether the file is trusted (Green), malicious (Red), or unknown (Orange). Clicking Lookup in TIE opens the TIE Certificate Reputations Details page, which allows you to view or edit the certificate reputation. Also, click the vendor name to review these additional details.

    • Subject — Name of the certificate vendor.

    • Issuer — Name of the certificate signing authority.

    • Certificate Reputation — Reputation of the certificate. Possible values are Known Trusted, Most Likely Trusted, Might be Trusted, Unknown, Might be Malicious, Most Likely Malicious, and Known Malicious. The color in which the Certificate Reputation is displayed indicates whether the certificate is trusted (Green), malicious (Red), or unknown (Orange).

    • Reputation Source — Indicates the reputation source. Possible values are TIE and GTI.

    • Public Key Algorithm — Indicates the algorithm used to create the public key to encrypt messages.

    • Public Key Length — Specifies the length of the public key in bits.

    • Public Key Hash — Specifies the public key hash.

    • Certificate Hash — Specifies the certificate hash.

    • Valid From — Indicates the date from which the certificate is valid.

    • Valid To — Indicates the date till which the certificate is valid.

  • System Name — Displays the endpoint where the event was generated.

  • User Name — Displays the name of the user logged on to the endpoint when the event was generated.

  • File SHA-1 — Displays the SHA-1 value of the file for which the event is generated.

  • File SHA-256 — Displays the SHA-256 value of the file for which the event is generated.

  • File MD5 — Displays the MD5 value of the file for which the event is generated.

Select Rule Group

Specifies the rule group for adding the created rules.

  • Choose existing — Updates an existing rule group with the defined rules.

  • Create new — Creates a rule group with the defined rules.

Add rule group to existing policy

Specifies the policy for adding the created or updated rule group.

Save

Saves the changes made.

Cancel

Exits without saving the changes, and returns to the Solidcore Events or Event Details page, as applicable.