AMSI/ETW events are not treated as a FDR event in SEDR

book

Article ID: 209531

calendar_today

Updated On:

Products

Endpoint Detection and Response

Issue/Introduction

In Symantec Endpoint Detection and Response (SEDR) 4.5.0 AMSI and ETW events are not treated as FDR events.

Cause

Environment: SEDR 4.5.0

Resolution

Broadcom Engineering resolved this issue in version 4.6.0. Please update to the latest build to receive this fix.