{"id":1825,"date":"2020-08-19T01:00:00","date_gmt":"2020-08-19T01:00:00","guid":{"rendered":"http:\/\/inswwdev.azurewebsites.net\/au\/insights\/uncategorized\/capture-application-lists-for-use-in-symantec-data-center-security-dcs\/"},"modified":"2024-09-17T07:37:50","modified_gmt":"2024-09-17T07:37:50","slug":"capture-application-lists-for-use-in-symantec-data-center-security-dcs","status":"publish","type":"post","link":"https:\/\/www.insentragroup.com\/us\/insights\/geek-speak\/cloud-and-modern-data-center\/capture-application-lists-for-use-in-symantec-data-center-security-dcs\/","title":{"rendered":"Capture Application Lists for use in Symantec Data Center Security (DCS)"},"content":{"rendered":"<p>Symantec DCS is a versatile tool which can be used to perform various lockdown tasks on Windows and UNIX\/Linux machines. It can do anything from application whitelisting through to a full least-privilege enforcement. It is a popular tool to use across many different operating systems, but its particularly useful on legacy machines which are no longer supported by the vendor. Symantec\u2019s support for old OSes currently stretches back as far as <span><a rel=\"noopener nofollow\" href=\"https:\/\/help.symantec.com\/cs\/dcs6.7\/DCS6_7\/v123231556_v110163010\/Intrusion-Prevention-Service-(IPS)-support-for-agent-features-of-6.7-MP2-and-6.7-MP3?locale=EN_US\" target=\"_blank\" data-anchor=\"?locale=EN_US\">Windows 2003, SP1<\/a><\/span>!<\/p>\n<p>When you create a prevention policy in DCS it is critical you understand what applications are in your whitelist. That is, which applications do you want to allow to have higher (or even full) access to resources on your system. DCS has an auto-discovery feature which allows you to do this automatically. However, one drawback to this method is that you need to already have the agent installed on a machine.\u00a0 The other drawback is you can\u2019t use it in conjunction with application lists. <span><a rel=\"noopener nofollow\" href=\"https:\/\/github.com\/Insentra\/PublicScripts\/blob\/main\/MakeDscCsv.ps1\" target=\"_blank\">I\u2019ve created <\/a><\/span><span>a script <\/span><span>you can use<\/span> to create an importable CSV for your application. The script will query any executable under a folder you specify and create the CSV with the following details:<\/p>\n<ul>\n<li>Full path to the executable<\/li>\n<li>Publisher name (if the code is signed)<\/li>\n<li>SHA 256 hash (if the code is unsigned)<\/li>\n<\/ul>\n<p>It will also add the application name and version to the comments field.<\/p>\n<p>The script requires SigCheck which is a SysInternals tool free for <span><a rel=\"noopener nofollow\" href=\"https:\/\/docs.microsoft.com\/en-us\/sysinternals\/downloads\/sigcheck\" target=\"_blank\">download<\/a><\/span>. Just make sure SigCheck is in the same directory as the script and run the script from PowerShell.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_ben_shorehill_09192020_img_1.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/d5b67d5a49524888bd449af54843b79b\" \/><\/p>\n<p>A folder selection window will open. Navigate to the directory in which you have your applications to be imported and click OK:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_ben_shorehill_09192020_img_2.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/3e68e0ae6f2042ad8abb33b7a447e06c\" \/><\/p>\n<p>Once the scan is completed, you will be prompted to save the CSV file. Save it in your preferred location:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_ben_shorehill_09192020_img_3.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/5dbdd33ac8d141caa894ba82a0608905\" \/><\/p>\n<p>Copy the CSV file you have saved to the management server or to a machine running the CSP console. Log into the console with your credentials and open the Prevention policy you wish to add the newly imported list to. In the policy, click Advanced and then click My Custom Sandboxes and lists:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_ben_shorehill_09192020_img_4.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/498431e5e23446818ec3050646ee2c77\" \/><\/p>\n<p>If you haven\u2019t created the list yet, click on the + Symbol to add a new list. Make sure you\u2019ve selected \u2018This defines a set of applications to be referenced later\u2019 as your Category and you\u2019ve added the Display Name and ID before selecting OK.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_ben_shorehill_09192020_img_5.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/7d72ec07b2a1411b9b4c3924550dad59\" \/><\/p>\n<p>Click edit on your list:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_ben_shorehill_09192020_img_6.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/8dda9aeeca554e4d9df4f35977753cdd\" \/><\/p>\n<p>If not already checked, check the box for Application Programs and click Edit:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_ben_shorehill_09192020_img_7.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/bda2292a2c254c60ab27299e7a4f3781\" \/><\/p>\n<p>Click import to import your newly created list. Navigate to the list and click Import. You will be prompted to either Append or Replace the list. Appending will leave the existing rules in place. Choose either option to import your list:<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.insentragroup.com\/wp-content\/uploads\/sites\/21\/2021\/02\/insentra_ben_shorehill_09192020_img_8.jpg\" alt=\"\" data-udi=\"umb:\/\/media\/73aa1f0374e940c4903d59a333b38e8c\" \/><\/p>\n<p>And that\u2019s it! Reference the list in your application rules.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Symantec DCS is a versatile tool which can be used to perform various lockdown tasks on Windows and UNIX\/Linux machines. It can do anything from application whitelisting through to a full least-privilege enforcement. It is a popular tool to use across many different operating systems, but its particularly useful on legacy machines which are no&hellip; <a class=\"more-link\" href=\"https:\/\/www.insentragroup.com\/us\/insights\/geek-speak\/cloud-and-modern-data-center\/capture-application-lists-for-use-in-symantec-data-center-security-dcs\/\">Continue reading <span class=\"screen-reader-text\">Capture Application Lists for use in Symantec Data Center Security (DCS)<\/span><\/a><\/p>\n","protected":false},"author":96,"featured_media":1826,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[21],"tags":[],"class_list":["post-1825","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cloud-and-modern-data-center","entry"],"_links":{"self":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts\/1825","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/users\/96"}],"replies":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/comments?post=1825"}],"version-history":[{"count":1,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts\/1825\/revisions"}],"predecessor-version":[{"id":21912,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/posts\/1825\/revisions\/21912"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/media\/1826"}],"wp:attachment":[{"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/media?parent=1825"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/categories?post=1825"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.insentragroup.com\/us\/wp-json\/wp\/v2\/tags?post=1825"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}