What's Covered
Create a Resource Target
Create a File Scan Policy
Create a File Parameter Selection
This document shows you how to create a whitelist policy for your reference system that targets a collection of computers, searches for Windows executables, and then adds any Windows executables to a whitelist.
...
- In the Security Manager Console, click the Policies tab.
- In the left pane, navigate to the Arellia Solutions > File Inventory > Policies folder.
- Right-click the Policies folder and click New > General Scheduled Client Task.
- In the Create Item dialog box, give the task a name and description.
- Under Client Command, click the Select link.
- In the Client Command dialog box, click File Scan Command.
- Click OK.
- Under Resource Targets, click the All Managed Computers (Target) link.
- In the Resource Targets dialog box, choose the endpoints you want to include in the policy.
- In the Create Item dialog box, click OK.
- Configure the new policy settings as follows:
- Turn on the new policy.
- Under File Specifications choose Executables in Windows Directories.
- Under Reporting Specifications choose Executions in Windows Directories not present in Security Catalogs.
- Configure the schedule interval for how often the file scan will execute.
Note: During the initial testing phase the file scan can be started manually using Windows Task Scheduler on the reference system.
- Click Save.
Create a File Parameter Collection
Once the file scan has run on the reference system(s) you will have a list of all executables in the Windows directories that are not contained in a security catalog.
You can create a file parameter collection that contains this list of files which can then be used in a whitelist policy
...
.
Create a file parameter collection by doing the following steps:
- In the Security Manager Console, click the Policies tab.
- In the left pane, navigate to the Arellia Solutions > Application Control > Filters > File Parameter Collections folder and create a new Inventory Filters
- Right-click the Inventory Filters folder.
- Click New > File Scan Results Filter (Policy).
- Give the filter a name and optional description.
- Click OK.
- Configure the parameters to reflect the File Scan policy settings
- Set the File Scan Policy to the policy created in the above steps
- Set the Reporting Filter to the same one that was configured in the above steps
- Set the Results to be Included
- Click Save
...