Effect of Data Loss Prevention (DLP) driver manipulation in windows driver directory
search cancel

Effect of Data Loss Prevention (DLP) driver manipulation in windows driver directory

book

Article ID: 390132

calendar_today

Updated On:

Products

Data Loss Prevention

Issue/Introduction

Windows user with Administrator privilege is able to rename and modify DLP agent drivers located at the C:\Windows\System32\drivers directory

* vfsmfd.sys

* vrtam.sys

* vmwcd.sys

Does this impact or hamper Agent functionality?

Environment

DLP Agent 15.8 

DLP Agent 16.0

DLP Agent 16.1

Cause

This is by design. The administrator will be able to modify these drivers.

Resolution

The DLP drivers in the driver directory are reloaded afresh once the agent is restarted. Hence renaming or modification of the driver does not impact agent functionality as the driver is clean reloaded.