Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 10 Current »

The default Arellia Agent and Arellia Application Control Solution (ACS) Agent installations allow Administrators to terminate those processes and services. This article will walk through how to prevent administrators from tampering with the Arellia Services.

To secure Arellia agents, do the following steps:

  1. Harden the Arellia Agent and ACS services against administrators (for details about service hardening, go to Service Hardening).
  2. Remove the debug privilege from Administrators by enabling the Remove Advanced Privileges for Interactive Users ACS policy.

    Warning

    Debug rights trump Remove Advanced Privileges for Interactive Users policy, so be aware anyone with debug rights will still be able to kill protected processes.

  3. Remove the terminate privilege from Administrators by creating a new process security action and then applying it via an Application Control Policy targeting the "Arellia.Agent.Service.exe" executable. (For details about adjusting process security, go to Adjust Process Security.)

How to enable process and service hardening using ACS and LSS

 

  • No labels