-
Posts
108 -
Joined
-
Last visited
Content Type
Events
Profiles
Forums
Posts posted by PsychologicalForm
-
-
7 minutes ago, Porthos said:
This truly belongs in the web FP section, Researchers will not see it here.
Apologies, I reposted in correct section. Was in a rush this morning.
-
The following URLs appear blocked by MBAM, however are Microsoft owned URLs that are built into Microsoft's Phishing Attack Simulator tool. Blocking the URLs doesnt allow Admins to see who all was phished in the simulation/training.
http://portal.docdeliveryapp.com http://portal.docdeliveryapp.net http://portal.docstoreinternal.com http://portal.docstoreinternal.net http://portal.hardwarecheck.net http://portal.hrsupportint.com http://portal.payrolltooling.com http://portal.payrolltooling.net http://portal.prizegiveaway.net http://portal.prizesforall.com http://portal.salarytoolint.com http://portal.salarytoolint.net
-
The following URLs appear blocked by MBAM, however are Microsoft owned URLs that are built into Microsoft's Phishing Attack Simulator tool. Blocking the URLs doesnt allow Admins to see who all was phished in the simulation/training.
http://portal.docdeliveryapp.com http://portal.docdeliveryapp.net http://portal.docstoreinternal.com http://portal.docstoreinternal.net http://portal.hardwarecheck.net http://portal.hrsupportint.com http://portal.payrolltooling.com http://portal.payrolltooling.net http://portal.prizegiveaway.net http://portal.prizesforall.com http://portal.salarytoolint.com http://portal.salarytoolint.net
-
sec
secured-login.net
I believe this domain is associated with KnowBe4 phishing educational tools.
-
Apologies. Appeared as if Chrome was the culprit. URLs are below in case....
http://https.secure-links.bloemlight.com/login
http://secure-mail.web.magnetonics.com/login -
We use a phishing program here at work to phish and educate users called KnowBe4. Some of the companies URLs are blocked by MBAM which renders the phishing tests useless.
https://support.knowbe4.com/hc/en-us/articles/203645138-Whitelist-Data-And-Anti-Spam-Filtering-Information
I will repost with a few exact examples shortly, but know there are many.
-
On 2/23/2018 at 12:14 PM, Cleatus said:
thx for the info--if you have any more as you think of, or come across-- post em
we (were) working on going to cloud version...about 1800 of em...many on VDI/VPN, etc
15 hours ago, djacobson said:@MikePahl318 MBAE is not broken, CScript launching in particular ways with homebrew apps, browser add-ons, office doc opening or printing scripts and can trigger it depending on what you are having CScript do or what calls it. If it is Explorer.exe or a browser calling it, that's a no no as that is typical exploit behavior, basically your browser has no business running command line. We will need to review your MBAE hit to give you a workaround for it. Did you have a case open for that already?
MBAE might not be broken (any more) but the cloud console is not production ready. We have a meeting at 2pm with our account rep to talk about features we need to see in production antimalware. A few are as follows
MFA
Endpoint Rename
Custom URL Blacklist
View active user
Endpoint Isolation
Can't Copy File Paths
Can't whitelist by policy
Viewing reports past 30 days
MBAM Cloud Admin Log
Business Support Forum / Portal
Poor VPN Performance
Install Errors
Easily Select Multiple Entries
No Filter in Detections
Poor Performance in RDS Environment
Clients show as offline
Console Periodic Sluggishness
Client is installed but not showing in console
.NET False Positives
Cscript False Positives
Automated Tasks
Apply Tags
Restrict App Execution
Can't view past detection statistics
Limited Deployment Methods
Non Existent User Management
User Management based on Policy
Set Data Retention to 180 days
Fix Breach Remediation
Shortcut to generate install pckgs on dashboard
Generate install packages based on policy
Cant Sort by Group/Policy or OS in endpoints menu
Failed Scans do not give detailed explanation -
Just read your whole post Kahml. Unfortunate situation there.
-
I think it's important to note i'm not, and never have, bashed MBAM. These are things we're talking about from a purely objective perspective.
We were extremely happy on MBAM EE. The issue was the dashboard look identical all through beta and into release, so we assumed development was halted. Then we had clients on users machines that carried the same version for a year, so we figured MBAM Cloud was getting all the dev attention. Jumping ship we felt like we landed in an early Alpha product (subjective) but the features simply are not there (objective), the bugs are there in great numbers (objective) and the support is not there either (objective).
MBAM is clearly the leader in definitions - it'll be hugely successful when it catches up in other areas. -
Cleatus, Coming from a long long long time Enterprise customer of MBAM, this pains me but here is my current list of reasons to probably hold off on Cloud
1.) Long list of issues using VPN with web detection enabled. (its broken)
2.) Cscript known bug (anti-exploit is broken)
3.) Unable to rename endpoint in console (DESKTOP-1R1CUKD.domain.local for example)(Client portion is broken)
4.) Unable to add URLs to custom/company blacklist
5.) Unable to copy file path of detected virus in Quarantine and Detections section. (Hover only, no expand or copy)
6.) Unable to view logged on user to any domain connected endpoint. -
I just re-submitted a ticket, i'll report back on whether this one is answered or not.
-
Just now, IT_Guy said:
Have you tried uninstalling everything and then reinstalling everything and then disabling everything?
Rinse and repeat.
Well, we tried both 1.) uninstalling everything as well as 2.) disabling everything. those worked great!
As far as reinstalling everything and enabling everything, both of those options break everything./s
-
2 hours ago, KDawg said:
Mike it pains me to hear about these issues you are experiencing
For future serious issues like these please do submit a ticket for fastest support
For the VPN issues this is a currently known defect with the web protection module, leaving the web protection module disabled should allow the other features to function without issues.
User added blocks is a highly requested feature we hope to release soon
Cscript exploit block is resolved in the latest version of anti exploit and we will be releasing it with the next update
Thanks for the response. Obviously with the need to disable web protection we feel we are leaving users at risk. Right now in order to leave our enterprise users non-impacted by MBAM we need to disable web protection, exploit protection, and continue to report URLs to the forums. Its painful.
Please help me out by expanding on your ticket comment. We have submitted tickets but we don't typically hear back. Can you confirm the process for me? Maybe i'm getting it wrong. -
-
Same here, no support response!
-
I won't turn this into a running list, but here is another one. I can not copy the location or expand it. There is no way to copy the location of the file of this false positive event into exclusions.
-
to expand on the VPN issue we have it added to exclusion list via vpn.XXXX.net as well as our IP
-
We have 80 days left on our MBAM Cloud licensing, and for the first time since I began using MBAM (I was an early enterprise adopter) we will likely not be renewing. MBAM Cloud feels extremely half baked, and the lack of options and features makes managing mbam cloud a nightmare right now. For example I can not even rename and endpoint in the cloud console or execute a scan from the Endpoint overview page.
With that said, our primary issue is the lack of Enterprise support options (forum coming soon?) and the bugs that have been introduced to MBAM Cloud that never existed in MBAM EE or previous versions before that.
Right now for example, any users that connects to our Split Tunnel L2TP VPN has to have MBAMs Web protection module disabled, or else IE/Chrome grind to a halt. Disabling the web protection module instantly resolves the issue.
We also can not add custom URLs or IPs to the blocked website lists, so as we get phishing attempts into our various enterprise mailboxes I am forced to create a forum entry and pray its adopted quickly - or blacklist it to our 8 firewalls and pray I beat users to the punch.A loyal but extremely disappointed and let down customer since Day 1,
Mike
-
To me, I am having a hard time selling mgmt on MBAM Enterprise. It's a lesser product than Consumer 3.0 to be honest.
With that said, still a big fan of what MBAM does and hope to see better Enterprise support moving forward.
-
-
-
Sorry for the delay. It will be looked into.
Many thanks
-
-
This is a legit website for downloading tools related to the Android Open Source Project
Site reported as having a Trojan?
in Website Blocking
Posted
CanaryTokens.com
Pretty common site, maybe a false positive?