You can now add trusted signers of Windows
or Mac processes to a whitelist in the ESM Console. When a file
is signed by a whitelisted signer, Traps permits the file to run.
For Windows signers, whitelisting a signer adds it to the list of
highly trusted signers (see the Malware Protection Flow).
To view and configure
trusted signers, your role must have the Trusted Signers privilege
enabled.
To whitelist a trusted signer:
Select PoliciesMalwareTrusted Signers.
Select the platform, Windows or Mac.
Select the action menu, and Add Signer.
Enter the name of the trusted signer.
(Mac only) Specify the SHA1 hash of the certificate
that signs the file.
To identify the hash for the certificate, review the local
agent logs after a file signed by the signer runs on the endpoint:
Using Cytool, set the log level for the trapsd daemon
log to 7 (debug).
(Optional) Provide a description indicating
why you whitelisted the signer.
Save the trusted signer.
After you save a trusted signer, you can edit or delete
it at any time.
The ESM Console logs any changes to the trusted
signers list and displays those logs from the MonitorESMHealth page.
To filter for changes to the trusted signers, filter the Report
Type column for any of the reports which begin with Trusted
Signer.