Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

USB Defender - Testing and Implementation

$
0
0

I have accomplished the following for USB Defender configuration:

  • Uploaded text file whitelist to USB Defender Local Policy connector,
  • Created matching list on LEM as user defined group,
  • Loaded USB Defender Extended connector,
  • Cloned rule to Detach Unauthorized Devices.

 

So I'm ready to test this, but before I do I need three questions answered:

  1. How do I test this on a limited set of machines, while being absolutely SURE it doesn't activate on the whole domain?
  2. I know that this disables ports when an unauthorized device is inserted, but what about devices that are ALREADY attached and being used? Does it shut down ports that are already in use or just when they are attached? ...what about reboots?
  3. Once an unauthorized USB device has been detached, is there a way to reactivate that port without PHYSICALLY reinserting it? If the detached device is added to the white list, will it become reactivated (without being reinserted)?

 

Thanks for any feedback!


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>