Endpoint Security Complete

Expand all | Collapse all

How to block autorun.inf with applicaiton control in SES

  • 1.  How to block autorun.inf with applicaiton control in SES

    Posted 16 days ago
    Hello,

    I've seen the SEP documentation on how to block autorun.inf with application and device control and have been through the app control policy in SES - it's not the right policy to block the file from what I can tell.  Can you advise on how one case create a policy in SES to block autorun.inf on any drive?

    Thanks,
    Rob Trimble
    TD Synnex Support Services


  • 2.  RE: How to block autorun.inf with applicaiton control in SES

    Broadcom Employee
    Posted 16 days ago

    Hi Rob, 

    By default, the Symantec Endpoint Protection client enables Application Control and the rule that blocks autorun.inf. You can disable this rule through Symantec Endpoint Protection Manager, but at this time you cannot disable this rule through a policy in the cloud console.

    I believe this to be true still. This is enabled by default, so you should not need to set anything up to block autorun.inf in ICDm/SES



    ------------------------------
    John Owens
    Strategic Support Engineer | Symantec Endpoint Security Division (SES)
    Broadcom Software
    ------------------------------



  • 3.  RE: How to block autorun.inf with applicaiton control in SES

    Posted 8 days ago
    Hello John,

    I have a similar issue.

    Client wants to allow "autorun.inf" file and client uses SES.

    Please guide me how I can disable this policy.

    Thanks,
    Rakesh
    TD Synnex Support Services


  • 4.  RE: How to block autorun.inf with applicaiton control in SES

    Posted 8 days ago
    Hello John,

    I have a similar issue.

    Client wants to allow "autorun.inf" file and client uses SES.

    Please guide me how I can disable this policy.

    Thanks,
    Rakesh
    TD Synnex Support Services


  • 5.  RE: How to block autorun.inf with applicaiton control in SES

    Broadcom Employee
    Posted 8 days ago
    Hi Rakesh,

    It is not possible. It is a hardcoded rule.

    ------------------------------
    John Owens
    Strategic Support Engineer | Symantec Endpoint Security Division (SES)
    Broadcom Software
    ------------------------------



  • 6.  RE: How to block autorun.inf with applicaiton control in SES

    Broadcom Employee
    Posted 6 days ago
    There's a major enhancement coming early next year that will allow you to disable this rule.