Security Evasion-MDM
Last updated on:
In this page
About the rule
Rule Type
Advanced
Rule Description
Whitelisting and installing an application and then updating control settings can be considered as security evasion.
Severity
Critical
Rule Requirement
Criteria
Action1: actionname = "uem_whitelist" Action2: actionname = "null" AND USERNAME = Action1.USERNAME Action3: actionname = "null" AND USERNAME = Action2.USERNAME AND USERNAME = Action1.USERNAME sequence:Action1 followedby Action2 within 10m followedby Action3 within 10m select Action1.MESSAGE,Action1.HOSTNAME,Action1.USERNAME,,
Detection
Execution Mode
realtime
Log Sources
ME Applications


