When running an EDAR scan, EDPA crashes, or the scan times out, when processing the Kernel files on M1 Macs and newer MacOS's.
The "Endpoint_-_<Endpoint Server Name>/agentlogs/'<Endpoint Name>'_<date and time>_ScanDetail_<log number>_0.log", includes the following Severe error:
Message: An error occurred while scanning file: /Library/Logs/Microsoft/mdatp/rotated/microsoft_defender_enterprise.log00002 (ErrorCode: | [SYMRESULT 0x80010006]) (ErrorMessage: COM error 0x80010006 occurred during detection.)
DLP 16.0.x
Apple MAC with Apple silicon (M1)
The private/var/db/KernelExtensionManagement/KernelCollections/ has new file/data from Apple that EDPA currently does not know how to handle and may crash.
When scanning an Apple Mac Endpoint that has the M1 chip, the exclusions list needs to be updated.
Workaround:
Add the exclude entries to the following file on Enforce:
Key to add to: com.vontu.manager.endpoint.discover.prepopulatedExcludeFilters
As follows:
$Windows$/*,/Applications/*,/System/*,/.Spotlight*,*.mp3,*.wma,*.wav,*.vox,*.aac,*.3gp,*.dat,*.iso,*.dmg,*.app,*.avi,*.mpeg,*.wmv,*.mov,*.mp4,*.dylib,*.jar,*.dll,*.exe,$ProgramFiles$/*,/opt/*,/sbin/*,/bin/*,/usr/bin/*,/Library/Manufacturer/*,*.so,/boot/*,/Applications/*,/System/*,/Library/Manufacturer/*,/private/var/db/KernelExtensionManagement/KernelCollections/*
Two Reasons the exclusion update is needed:
The exclusions have been added to DLP 16.1.