Hey guys,
I would like to clear the trusted vendors list, would it have any conflict with my system stability?
I would like to clear the trusted vendors list, would it have any conflict with my system stability?
Last edited:
Please provide comments and solutions that are helpful to the author of this topic.
Thank you, I just checked CIS file list and you are right, it did gave a few files an unrecognized rating, assuming I don't install new software each day and I change the file rating to trusted, can it conflict with anything on my system and cause any issue? and does CIS update still restore all the TVL back to default?
So if whatever is on local TVL is on cloud TVL, then whats the benefit of removing vendors from local TVL?
I mean suppose you are removing vendors that you think shouldn't be there for some reasons but if the cloud TVL has all the local TVL vendors too then wont the product from those vendors still be trusted with cloud checkup?
Why the file will be autosandboxed for the removed vendors?You remove vendors on local TVL because you intend to never install applications from those vendors. If any files from the removed vendors are introduced to your system, then HIPS will generate "Digitally signed, but not on TVL" alerts. Of course, you have to have HIPS enabled for the HIPS alerts to appear.
Also, file will be auto-sandboxed since CIS will treat the file (even if digitally signed - because you removed the vendor from local TVL) as Unrecognized.
Why the file will be autosandboxed for the removed vendors?
Wont the file be checked with cloud on run & vendor be found on cloud TVL?
Not always, do you mean sometimes file is correctly trusted as found in cloud TVL? I say correctly trusted coz this is the way it should work if cloud has full TVL i.e local TVL too, right?Not always.
I have asked about why this is the case and received no technical infos.
I too think so.I personally think customizing the local TVL is a waste of time since there is no clear infos on how it works under all circumstances.
Not always, do you mean sometimes file is correctly trusted as found in cloud TVL? I say correctly trusted coz this is the way it should work if cloud has full TVL i.e local TVL too, right?
Ok, got itSometimes digitally signed files by a vendor in cloud TVL are not treated as Trusted and vendor is not added to local TVL.
It has been reported for a long while by now.
For example, some Windows files will not be treated as Trusted, even though digitally signed by Microsoft (even with Microsoft in local TVL).
There are various bugs that affect TVL.