Jump to content

technikarc

Members
  • Posts

    4
  • Joined

  • Last visited

    Never

Posts posted by technikarc

  1. After about 12 hours Kaspersky Security Center MMC Error.cmd appeared in HIP settings search menu and I was able to add it to trusted group. It should launch Kaspersky Security Center 11.msc.
    Then I couldn't launch Kaspersky Security Center 11.msc even directly or find it in HIP settings search menu. I sew the same error message as with Kaspersky Security Center MMC Error.cmd. And again I couldn't find Kaspersky Security Center 11.msc in HIP settings search menu but could find it on clients workstation in HIP Untrusted group and add it to Trusted group after disabling policy.

    Problem was solved adding additional Inventory task.

    It should be cleared-out for users that this task is needed HIP functionality to fully work.

    • In KNA Policy I've created two locations Test1 and Test2. Synced with the client. Checked with klnagchk.exe - everything was fine.
    • In KNA Policy I've deleted these two locations Test1 and Test2. Synced with the client. Checked with klnagchk.exe - everything was fine.
    • In KNA Policy I've created location BANANA. Synced with the client. Checked with klnagchk.exe - in Locations section it still shows Test1 and Test2 locations.
    • If I delete BANANA, Locations section is empty. But if I create any other location, Test1 and Test2 is back again and again.

    It affects only one client. Tried to restart it several times. How to force client's KNA to get correct policy settings?

     

    KSC / KNA v11.0.0.1131

    KES v11.2.0

  2. ​Application launches if i disable HIP in the policy.

     

    Application is blocked if HIP is enabled and I can find the log about it:

    Event type:     Application placed in restricted group
    Application:     Kaspersky Security Center MMC Error.cmd
    Application\Name:     Kaspersky Security Center MMC Error.cmd
    Application\Path:     C:\Soft\Kaspersky Security Center\
    Application\Process ID:     7828
    User:     VM1\Admin (Active user)
    Component:     Host Intrusion Prevention
    Result\Threat level:     Low
    Result\Precision:     Exactly
    Action:     Application placed in group
    Object:     KLAppUntrusted
    Object\Type:     Application group
    Object\Path:     KLAppUntrusted
    Object\Name:     KLAppUntrusted
    Reason:     Trust group cannot be defined

     

    In HIP inside policy settings I cant find this application nor in any group nor can add it using search with any masks or time intervals. It’s just not there.

     

    How can I whitelist this application so HIP would not block it?

     

    KSC / KNA v11.0.0.1131

    KES v11.2.0

×
×
  • Create New...