This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

Looking to create a rule when portable apps are used.

Wanted to see if the SEM has any abilities to capture the use of a portable application?  Software installed are controlled but wanted to see if we can capture the use of portables on the servers and get an email. Let me know if you have tired to set up a rule similar to this.

Thanks, 

Parents
  • Process logging isn't always turned on in Windows, but if it is then it's possible for you write rules to check for any kind of process.  The slightly tricky part is establishing which processes are ok and which aren't.  What I've seen people do for some similar cases is build a rule initially that builds a list of all the currently active processes in the org, then you let that rule run for a while where it's action is just to add the process names to a group list.  Review the list to make sure nothing sketchy is already in the list. Once you have it dialed in you switch to a rule that alerts any time a process starts that isn't on the white list.

    So it doesn't exactly look for portable processes, but it does track for any new process introduced to your environment.

Reply
  • Process logging isn't always turned on in Windows, but if it is then it's possible for you write rules to check for any kind of process.  The slightly tricky part is establishing which processes are ok and which aren't.  What I've seen people do for some similar cases is build a rule initially that builds a list of all the currently active processes in the org, then you let that rule run for a while where it's action is just to add the process names to a group list.  Review the list to make sure nothing sketchy is already in the list. Once you have it dialed in you switch to a rule that alerts any time a process starts that isn't on the white list.

    So it doesn't exactly look for portable processes, but it does track for any new process introduced to your environment.

Children
No Data