Unsigned process has been routed to deny_ps after applying Critical System Protection (CSP) Intrusion Prevention policy
search cancel

Unsigned process has been routed to deny_ps after applying Critical System Protection (CSP) Intrusion Prevention policy

book

Article ID: 446980

calendar_today

Updated On:

Products

Critical System Protection

Issue/Introduction

The customer applied CSP Intrusion Prevention policy and observed that unsigned processes are routed to deny_ps and prevented to start

Environment

CSP 8.0.2

Windows 10

 

Cause

Critical System Protection (CSP) Intrusion Prevention policies have additional protection defined in the Global Policy Option Block Execution of Unsigned Binaries. 

Resolution

If you need to allow execution of unsigned binary (not recommended) an additional rule under Global Policy General Settings-->Allow Execution of Unsigned Binaries has to be created with the full program path to the processes that were routed to deny_ps