The most recent content from our members.
I am creating a whitelist of USBs and have a few questions. First, almost all of the example rules I have seen only contain SystemStatus.EventInfo = *attached* and do not include SystemStatus.EventInfo = "USB Input" Is there a reason why others have left off these USB alerts? Also when trying to add the USB Input IDs to…
Hi guys, We are looking to use LEM to implement USB blocking. I understand how to create a whitelist, uploading the PID's of the stick etc. My question is this: Lets just say we have a whitelist with a tonne of PID's in it. A user needs to have a new device whitelisted and I upload a text file containing only the PID of…
Tested and working for: Our e-mail response connector is enabled and working. We have enable the USB-Defender Policy connector and uploaded a notepad for USB devices that are white listed. Also, included the USB devices ID into the "Authorized USB Devices" group. Unauthorized USB is now currently detached instantly if…
Hi, We've finally got around to looking at implementing USB Defender but only require it in a file audit capacity. So we don't need whitelist or UDLP items, there's GPO in place and AD secgroups to control USB access. I have one development Windows 7 citrix VDI desktop accessed via a Wyse terminal and I can see…
I was wondering if there was a quick way to uninstall USB Defender? I know you can run the remote uninstaller and then reinstall, but I was wondering if there was a way to just remove USB Defender without doing a full uninstall/reinstall? Thank you!
Hey all - I bumped into a scenario where Fujitsu Scanners extraneous info was logging differently on the LEM depending on what USB port it was plugged into. I wondered if maybe this was applicable to other devices like our USB storage drives (which could be problematic). I have tested a few by plugging them into different…
We have had the USB Defender rule on our LEM for the duration of time I have been with my organization. It's connected to the UDLP policy and they opted to use a notepad document to catalog the Windows ID numbers that are to NOT to be blocked by the policy. So the rule is: EventInfo: *Mass Storage Device* AND ExtraInfo:…
It looks like you're new here. Sign in or register to get started.