When the Wintrust Policy is enabled, one of four Wintrust alerts can be generated on your Endpoint Security (HX) Server, depending on the detection strategy that caused the alert.
Alert Value | Attribute Field | Description |
|---|---|---|
| | A registry entry that does not correspond to the expected Subject Interface Package (SIP) |
| | A registry entry that does not correspond to the expected Trust Provider (TP) |
| | The Wintrust binary is not properly signed. |
| | The Wintrust subsystem provides false outcomes for known untrusted samples. |