Quantcast
Channel: Symantec Connect - Endpoint Protection - Discussions
Viewing all articles
Browse latest Browse all 10484

Killing the SEP service

$
0
0
I need a solution

Hello everyone, recently we had a PT assesment in our SEP enviroment and the PT team had reported that they were able to succuesfully kill/bypass the SEP service. They also had a tool which they run and it disables the SEP. Also they used the taskkill command in cmd with local admin privalages and they bypassed it. Even though we already have the below enabled on the SEP side

  1. Password protection is enabled to stop the service. Verified it if someone tries to do smc- stop, we are prompted to supply the pasword.
  2. Password protection is enabled to uninstall the agent. Tried to uninstall from control panel, we are prompted to supply the password.
  3. If we try to go the task try right click on SEP shield, Disable Symantec Endpoint Protection is greyed out.
  4. Temper protection is enabled and the action for it is to Block and Log.

I also came across the below article and it works like this.

https://www.symantec.com/connect/forums/how-preven...

I am wondering how they SEP service can get killed even though temper protection is already enabled. 

0

Viewing all articles
Browse latest Browse all 10484

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>