Last edited by Draiden 11 May 2023 15:16.

Last edited by Draiden 10 May 2023 18:49.

Last edited by Draiden 04 May 2023 21:16.



So its been awhile. I tooked my vacay and came back saw this alert from my 2nd layer SIEM.
does EDR intentionaly going to turn off firewall?

And maybe this is why my EDR agent Icon got red dots?




EDIT:

I found out that during CC+ES correlation when triggered ES will do deep scan. So since its hosted on a server, agent needs ask for turning it off while doing some errunds.

Thanks guys!

EDIT:

Case solved. Just clumsy after a long vacation..

CLELUQMAN has solved this question and earned 40 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins, 20 coins of bounty and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

have u solve this? i think the EDR turn off the firewall is temporary , maybe it is updating or scanning.
Is this answer helpful?
Gomu Lv2Posted 09 May 2023 08:40
  
it indicate that it detects a malware.
Franky Lv3Posted 09 May 2023 08:36
  
However, an EDR solution may detect that a firewall is interfering with network access or other system functions in some cases.
eram Lv1Posted 09 May 2023 07:19
  
A recent software update or system configuration change could have caused the EDR agent and firewall to stop working correctly. Sometimes updates or changes to your system can inadvertently cause conflicts with security software and result in malfunctions.
Pat Lv4Posted 09 May 2023 06:55
  
In some cases, however, an EDR solution may detect that a firewall is causing issues with network connectivity or other system functions. In such cases, the EDR solution may recommend disabling the firewall temporarily to troubleshoot the issue. However, this would typically be done with the explicit knowledge and consent of the system administrator or other responsible parties, and only as a temporary measure until the issue can be resolved.
Imran Tahir Lv4Posted 08 May 2023 21:53
  
Get help with technical support
Zonger Lv4Posted 08 May 2023 18:15
  
The command mentioned, "netsh advfirewall set allprofiles state off," is used to disable the Windows Firewall for all network profiles (Domain, Private, and Public). It turns off the firewall protection, allowing all incoming and outgoing network traffic without any filtering or blocking.

However, it's important to note that disabling the Windows Firewall can expose your computer or network to potential security risks. The firewall acts as a barrier between your system and the outside network, helping to prevent unauthorized access and protecting against malicious threats.

If you choose to disable the firewall temporarily for troubleshooting purposes or other specific reasons, make sure to take appropriate precautions, such as ensuring that your computer is not directly connected to the internet or being used in an insecure network environment.

After you have completed your intended tasks, it is strongly recommended to enable the Windows Firewall or configure it to allow only necessary traffic based on your network security requirements. You can enable the firewall again using the command:

netsh advfirewall set allprofiles state on


Always prioritize the security of your system and network by implementing a comprehensive and robust security strategy.
Yboom Lv2Posted 08 May 2023 17:43
  
Please contact technical assistance.
Donsadam Posted 08 May 2023 17:39
  
The presence of red dots on the EDR agent symbol might indicate that the EDR agent is malfunctioning or that it is not interacting correctly with the security dashboard or server.
CptArmando Lv2Posted 08 May 2023 17:33
  
You may need to analyze the logs and alarms from your SIEM and EDR systems, as well as any other security software installed on the impacted endpoint, to investigate this issue.

I Can Help:

Change

Moderator on This Board

18
8
0

Started Topics

Followers

Follow

Trending Topics

Board Leaders