Skip to main content
kwernecke
Staff
Staff
May 4, 2022

Technical Tip: FortiEDR - Fortinet block of process, creating a unique dll each time

  • May 4, 2022
  • 0 replies
  • 449 views
Description This article describes how to set a proper exception on events with unique dll's.
Scope FortiEDR.

Solution

In the following events with the following file examples:

 

tmpCE1B.tmp.exe
or
â„›*7a4ec619-1206-475f-83ac-eafd7dd149e6#2-0.dll

or  tmpXXX.tmp.exe

 

(Where XXX is an alphanumeric value), it is okay to set wildcard on them like this tmp*.tmp.exe.

 

Or

 

If it always starts with â„›* then you can use a wildcard like â„›**.