This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Tamper Protection

Just wondering if there is any chance in future releases of the tamper protection feature being extended to include the application control settings (well, I say settings but I really meam stopping them from disabling it?)

Thanks,

D

:9029


This thread was automatically locked due to age.
Parents
  • That was precisely my point. In an environment where most users are Power User or have Local Admin rights the Tamper Protection is useless. Also, many rootkits and priveledge escalation attacks attempt to stop these services with local admin rights under context of the current user priveledges.

    But I disgress... there are ways that you can manage this security, just not within Sophos natively.

    If you are in a AD environment using Group Policy, you can set these services as protected at the Domain Admin level. This prevents even users with Local Admin rights from stopping or disabling these particular services.

    Under your Default Domain Policy (or any OU policy for that matter) -> Computer Configuration -> Windows Settings -> Security Settings -> System Services.

    Define each Sophos service there and remove the Administrators group from each while adding Domain Admins. Make sure to leave SYSTEM permission as is.

    :10045
Reply
  • That was precisely my point. In an environment where most users are Power User or have Local Admin rights the Tamper Protection is useless. Also, many rootkits and priveledge escalation attacks attempt to stop these services with local admin rights under context of the current user priveledges.

    But I disgress... there are ways that you can manage this security, just not within Sophos natively.

    If you are in a AD environment using Group Policy, you can set these services as protected at the Domain Admin level. This prevents even users with Local Admin rights from stopping or disabling these particular services.

    Under your Default Domain Policy (or any OU policy for that matter) -> Computer Configuration -> Windows Settings -> Security Settings -> System Services.

    Define each Sophos service there and remove the Administrators group from each while adding Domain Admins. Make sure to leave SYSTEM permission as is.

    :10045
Children
No Data