In Proactive Configuration, remove the last or All Applications - Unrecognized policy from Auto-Containment. Place the three policies in the same order at the bottom in Auto-Containment.
Action - Run Virtually, File Group - All Applications, File Origin - Removable Media, File Rating - Trusted, File Age - Less than 1 hour
Action - Run Virtually, File Group - All Applications, File Origin - Internet, File Rating - Trusted, File Age - Less than 1 hour
Action - Run Virtually, File Group - All Applications, File Rating - Unrecognized, File Age - Less than 1 hour
My POCs are not blocked.
The reason is that the files contained in the ISO container have the creation time of the original files used when the attacker created the ISO on his computer. For example, TDSSKiller has the original date from the year 2019.
The same applies to all removable media mounted by Windows handler and archives unpacked by Windows built-in unpacker.
So the file age must be unlimited for the first two rules to block the POCs that use removable media or archives.
Edit.
7-Zip unpacks archives while adding the current creation time. So when 7-Zip is configured to open by default archives and disk images, the 1-hour File age rule will work as intended.
However, the 1-hour File age rule will not work for executables stored on flash drives.
Last edited:

