Security Evasion-MDM
Last updated on:
In this page
About the rule
Rule Type
Advanced
Rule Description
Whitelisting and installing an application and then updating control settings can be considered as security evasion.
Severity
Critical
Rule Requirement
Criteria
Action1:
actionname = "Application whitelist events"
Action2:
actionname = "Application Management events" AND USERNAME = Action1.USERNAME
Action3:
actionname = "Successful control setting modifications" AND USERNAME = Action2.USERNAME AND USERNAME = Action1.USERNAME
sequence:Action1 followedby Action2 within 10m followedby Action3 within 10m
select Action1.MESSAGE,Action1.HOSTNAME,Action1.USERNAME,Action2.MESSAGE,Action2.HOSTNAME,Action2.USERNAME,Action3.MESSAGE,Action3.HOSTNAME,Action3.USERNAME
Detection
Execution Mode
realtime
Log Sources
ME Applications


