Serious Discussion Deep Instinct | Deep Learning AI Cybersecurity Platform

simmerskool

Level 38
Verified
Top Poster
Well-known
Apr 16, 2017
2,784
Hello I recently purchased a license but I dont know exactly how to add an exclusion.
DeepInspect is throwing alerts of Steam code injection and what I can only do is to put code inject behaviour to 'detect' and not to 'prevent'.
Any idea? Thanks
I had to add exclusion for one "false+" and recall you can add it very specifically just for that app and for the issue it spotted as defined in the alert notice / report. But that was 2 months ago and I don't recall the exact procedure. I do recall that support at cyberforce was helpful, and I followed their instructions and created that specific exception for that app and it then ran aok.
 

Kongo

Level 36
Verified
Top Poster
Well-known
Feb 25, 2017
2,597
Hello I recently purchased a license but I dont know exactly how to add an exclusion.
DeepInspect is throwing alerts of Steam code injection and what I can only do is to put code inject behaviour to 'detect' and not to 'prevent'.
Any idea? Thanks
Policy --> Allowlist

There you can add exclusions by file hash, process, file path or exclude it from the behavioural analysis. After you added it, you can manually check for updates in the Deep Instinct client to apply the changes to the policy.
 

simmerskool

Level 38
Verified
Top Poster
Well-known
Apr 16, 2017
2,784
Policy --> Allowlist

There you can add exclusions by file hash, process, file path or exclude it from the behavioural analysis. After you added it, you can manually check for updates in the Deep Instinct client to apply the changes to the policy.
I also recall that you can select & exclude a very specific threat, console presents a list and it showed me 4 items but was a dropdown list which was not immediately obvious, which lists several more "threats" -- eg my block was Reflective DLL Injection, I excluded that threat for that app, and the app then ran great. That is the only "false+" that Di has found after running +60 days.
 

Kongo

Level 36
Verified
Top Poster
Well-known
Feb 25, 2017
2,597
my DI client just updated from 4.0.0.9 to 4.0.0.14

Does anybody know where to find the patchnotes?
 
  • Like
Reactions: Nevi

Kongo

Level 36
Verified
Top Poster
Well-known
Feb 25, 2017
2,597
my Di shows v. 4.0.0.9 both before and after I hit the "check for updates" button...:unsure: we have different resellers, yes?? :unsure: :unsure:
Maybe check again in a couple of hours. We both got it from the same reseller and even if we didn't, that shouldn't be an issue. Do you have automatic upgrade of the client enabled in your online dashboard?
 

cartaphilus

Level 11
Verified
Top Poster
Well-known
Mar 17, 2023
536
Hello I recently purchased a license but I dont know exactly how to add an exclusion.
DeepInspect is throwing alerts of Steam code injection and what I can only do is to put code inject behaviour to 'detect' and not to 'prevent'.
Any idea? Thanks
It's done via connecting to the web management console. There you can add exceptions to folders and files.

For the new *.14 version. Any changelog from *.09?
 

simmerskool

Level 38
Verified
Top Poster
Well-known
Apr 16, 2017
2,784
Maybe check again in a couple of hours. We both got it from the same reseller and even if we didn't, that shouldn't be an issue. Do you have automatic upgrade of the client enabled in your online dashboard?
Automatic, I assume yes, but I will check, thanks
 
  • Like
Reactions: Nevi and Trident

monoloko88

New Member
May 12, 2015
2
Policy --> Allowlist

There you can add exclusions by file hash, process, file path or exclude it from the behavioural analysis. After you added it, you can manually check for updates in the Deep Instinct client to apply the changes to the policy.
ah I think that was my problem, I was adding the exclusion file but I did not manually check for updates so the problem still persisted and I was thinking, it wasnt running well
thanks
 

simmerskool

Level 38
Verified
Top Poster
Well-known
Apr 16, 2017
2,784
New version of Deep Instinct is blocked by Smart App Control. I really hate that you can't add exclusions to it. It's so annoying. Now I have to disable Smart App Control until I reset my Windows again... :poop:
still 4009 at 1730 utc monday, will login to Di console soon. On this win10 doubt I have SAC running (if SAC runs on win10 -- looks like win11 feature...) :unsure:
 

simmerskool

Level 38
Verified
Top Poster
Well-known
Apr 16, 2017
2,784
New version of Deep Instinct is blocked by Smart App Control. I really hate that you can't add exclusions to it. It's so annoying. Now I have to disable Smart App Control until I reset my Windows again... :poop:
Made the time to login to DeepInstinct console and 4.0.0.14 is sitting there waiting to be downloaded. Under Policy | Windows | D-Client Automatic Upgrade is "Disabled" -- not sure if that is default or if I did that on purpose. If me, I don't recall why. So manually deploying ..14 after I post this.

EDIT downloaded 4.0.0.14 installer, ran it but D-Client still reading 4.0.0.9 (assume user error) sent email to support... o_O
 
Last edited:

Kongo

Level 36
Verified
Top Poster
Well-known
Feb 25, 2017
2,597
Made the time to login to DeepInstinct console and 4.0.0.14 is sitting there waiting to be downloaded. Under Policy | Windows | D-Client Automatic Upgrade is "Disabled" -- not sure if that is default or if I did that on purpose. If me, I don't recall why. So manually deploying ..14 after I post this.

EDIT downloaded 4.0.0.14 installer, ran it but D-Client still reading 4.0.0.9 (assume user error) sent email to support... o_O
Why don't you just set it to automatic and let DeepInstinct do the rest? Maybe this works.
 

Andy Ful

From Hard_Configurator Tools
Verified
Honorary Member
Top Poster
Developer
Well-known
Dec 23, 2014
8,592
Didn't @Andy Ful found something that can be used to enable/disable SAC anytime? :unsure:

I wrote about it a few times.
There is a proven method of turning SAC ON by using CMD from the Recovery Environment (it is different from CMD in Safe Mode). One has to use the boot method:
Troubleshoot >> Advanced options >> Command Prompt, and run regedit.exe . Next, one has to find the drive with the installed Windows (it can be different from C:) and load the SYSTEM HIVE from the Windows\system32\config. In this way, one can change two registry values:

1689633342501.png


1689633269139.png


The data for the registry values VerifiedAndReputablePolicyState and VerifiedAndReputablePolicyStateMinValueSeen are equal to 0, but should be changed to 1.

On some computers, SAC can be turned ON by changing only the first value (VerifiedAndReputablePolicyState), and this can be done without a problem from the normal Windows session after running regedit.exe with Admin rights. This method works well on my 2 computers but does not work on the third. It can be found via Google, for example:
In the article are also included the .reg files to automate the job without manual registry editing.(y)

Edit.
I used the first method to change the values VerifiedAndReputablePolicyState and VerifiedAndReputablePolicyStateMinValueSeen. Now, the second method works also on my third computer. :)
 
Last edited:

Kongo

Level 36
Verified
Top Poster
Well-known
Feb 25, 2017
2,597
I wrote about it a few times.
There is a proven method of turning SAC ON by using CMD from the Recovery Environment (it is different from CMD in Safe Mode). One has to use the boot method:
Troubleshoot >> Advanced options >> Command Prompt, and run regedit.exe . Next, one has to find the drive with the installed Windows (it can be different from C:) and load the SYSTEM HIVE from the Windows\system32\config. In this way, one can change two registry values:

View attachment 277270

View attachment 277269

The data for the registry values VerifiedAndReputablePolicyState and VerifiedAndReputablePolicyStateMinValueSeen are equal to 0, but should be changed to 1.

On some computers, SAC can be turned ON by changing only the first value (VerifiedAndReputablePolicyState), and this can be done without a problem from the normal Windows session after running regedit.exe with Admin rights. This method works well on my 2 computers but does not work on the third. It can be found via Google, for example:
In the article are also included the .reg files to automate the job without manual registry editing.(y)
Thanks a lot for taking the time to explain it again. Appreciate it! (y)
 

simmerskool

Level 38
Verified
Top Poster
Well-known
Apr 16, 2017
2,784
Why don't you just set it to automatic and let DeepInstinct do the rest? Maybe this works.
:ROFLMAO: of course you are correct! factoid, downloading that file and trying to manually install it on computer where Di is already installed results in update failure. The only way to get update is to change the policy in console to automatically update ENABLE (or so I'm told by support tech). Did that and ..14 is now installed on first, one more to go. Do you recall: is that feature default setting enabled or disabled, I just don't recall changing it if default is Enabled (& I take notes too)
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top