Verify DLL binary

Prev Next

When the WINTRUST.dll binary is tampered with to subvert Wintrust authentication, the agent generates a TAMPER_PROTECTION alert, as described in Wintrust Alerts . By default, the "Verify Binary" setting is enabled in the Wintrust Verification Policy. When enabled, an alert will be generated on your Endpoint Security (HX) Server if WINTRUST.dll is determined to be an unsigned or modified binary.

To change the Verify Binary setting on your host endpoints:

Important

The following configuration only applies to Windows xAgent versions 35.31.0 and above.

  1. Log in to the Web UI as an administrator.

  2. From the Admin menu, select Policies to access the Policies page.

  3. From the Policies table, click the Agent Default Policy link to go to the Edit Policy page.

  4. Select the Tamper Protection tab.

  5. Toggle the ON/OFF switch next to Verify Trust Binary.

  6. Click Save to save the policy settings.