Check: ENS-TP-000222
Trellix ENS 10.x STIG:
ENS-TP-000222
(in versions v3 r2 through v2 r5)
Title
(U) The Trellix ENS Threat Prevention On-Demand Scan must be configured to scan boot sectors. (Cat II impact)
Discussion
(U) Boot sector viruses will install into the boot sector of a system, ensuring that they will execute when the user boots the system. This risk is mitigated by scanning boot sectors at each startup of the system.
Check Content
(U) Access the ePO server console. Select Menu >> Policy >> Policy Catalog From the "Product" list, select "Endpoint Security Threat Prevention". From the "Category" list, select "On-Demand Scan". Select each configured On-Demand Scan policy. Verify What to Scan >> "Boot sectors" is selected. If What to Scan >> "Boot sectors" is not selected, this is a finding.
Fix Text
(U) Access the ePO server console. Select Menu >> Policy >> Policy Catalog From the "Product" list, select "Endpoint Security Threat Prevention". From the "Category" list, select "On-Demand Scan". Select each configured On-Demand Scan policy. Select the What to Scan >> "Boot sectors" option. Click "Save".
Additional Identifiers
Rule ID: SV-228256r961191_rule
Vulnerability ID: V-228256
Group Title: SRG-APP-000277
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-001241 |
Configure malicious code protection mechanisms to perform periodic scans of the system on an organization-defined frequency. |
Controls
Number | Title |
---|---|
SI-3 |
Malicious Code Protection |