On Windows devices, if you enforce PowerShell Constrained Language Mode for all users, Agent is unable to run successful scans. You can improve success with these Agent scans by adding Arctic Wolf as a trusted publisher in your application control software or virus scanning software.
Note: After you configure your Windows device to trust Agent scanner signed files, you must contact your Concierge Security® Team (CST) to enable the feature.
These resources are required:
- An MR license
- Windows administrative permissions
- Download the appropriate signature references:
- Using Command Prompt, run this command to verify the hash value of the zip file or files from step 1:
certutil -hashfile <zip_file_location> <hash_type>
Where:
<zip_file_location> is the location of the zip file. For example, c:\Users\User_Name\Downloads\rse_signature_references.zip.
<hash_type> is the hash type: SHA256, SHA1, or MD5.
The returned hash value for the
rse_signature_references.zip file should match one of these options:
- SHA256 —
977941168282fdaf8a2d0e396fa0cbdced838e2020da3aab6e250ee232120de3
- SHA1 —
d141de57672508e0ec552e303e3726d36b1c016e
- MD5 —
b136740957c44b9ea5a08532d41ceb06
The returned hash value for the
rse_signature_references_old.zip file should match one of these options:
- SHA256 —
b0d34aacf75aa8779807a7363a3384303ef4100f1588605303ca49fd03e8ac36
- SHA1 —
2dd5a735f40d786313ad67d310b48fa6f3fb6d73
- MD5 —
a4022e4040fc7a9ea68fd0440069ba5a
- Extract the zip file or files.
- On each Windows endpoint that has Agent installed, complete these steps:
- Open the application control software or virus scanning software that is blocking the Agent scan. For example, AppLocker or App Control for Business (formerly known as Windows Defender Application Control [WDAC]).
- Create rules to trust the appropriate
SignatureReference files that are located in the folder that the ZIP file extracted to.
- Save your changes.
- Contact your Concierge Security® Team (CST) at security@arcticwolf.com and request them to enable this feature.