Jump to content

Georgi Stoychev

Members
  • Posts

    29
  • Joined

  • Last visited

Posts posted by Georgi Stoychev

  1. Hello,

    We have several employees who travel often and from time to time, they connect to client networks. Recently, one of them connected to such network and in our ESET protect on-prem console, we received multiple alerts from the Firewall module that Security vulnerability exploitation attempt was detected on the endpoint. There is a high chance that this really was such an attempt, but our employee was not aware of this, and he said that he hasn't seen such notification. Is there something we can do to show these notifications on the endpoints as well, since we couldn't find such option in our console?

  2. Hello,

    We are using Chocolatey in our corporate environment, and started to receive thousands of alerts about this file being malicious - "file:///C:/ProgramData/chocolatey/helpers/functions/Get-ChocolateyWebFile.ps1".  For the moment, we have added an exclusion in our ESET Management Console, since we received about 1000+ alarms. Can you tell us how can we investigate further what could be the cause of it? It seems pretty serious.

  3. Hello,

    Couple of days ago, we changed our ESET Protect On-Prem server certificate, as it was about to expire, and the old certificate was revoked. Today we see that several computers, which were offline when we replaced the certificate, are not connecting to the server. We saw in the logs in "C:\ProgramData\ESET\RemoteAdministrator\Agent\EraAgentApplicationData\Logs" an error message "Error: Remote server peer certificate is not trusted by this agent. Details: NodVerifyCertificateChain failed: NodVerifyTrustResult: 42, NVT_NotTrusted, X509ChainStatus: 0x4, X509CSF_Revoked, certificate"

    We have a backup of the old server certificate, but would like to use the new one. Is there some step that we may have missed when we changed the old certificate? We haven't restarted the server after the change. Could that be the issue?

  4. Hello,

    One of our colleagues received an alert that the update information is not consistent and that he should restart his computer. After the restart, the following notification appeared:

    image.png.0e78115827ca571f28235f4ccf9cf026.png

     

    After a few minutes, we checked the ESET Protect console and there wasn't anything disturbing about that particular computer and the status was OK. What could be the cause of this issue and should we be worried about it?

  5. Hi all,

    Not sure if it's already discussed before, as I can't find anything in the forums, nor in the KB. So, is there a way to update the Agent on endpoint devices with Puppet when the peer certificate has expired, instead of using the GPO method, which is explained here? I am asking since the GPO method requires (at least with us) couple of gpudate /force runs and couple of restarts of the client machines.

  6. Hello,

    We have enabled several notifications in our ESET Protect console, like ERA Alert for Firewall events, ERA Alert for Antivirus events, etc... The question is that when we receive a notification from the type "ERA Alert for Firewall events", the user field is empty, but the user is present in other notifications, such as "Malicious file detected". We've checked the configuration on several of the notification types and they seem identical. Could this be some kind of a bug? I will attach screenshots, which better describe the issue.

     

    firewall_event_notification_settings.png

    malicious_file_notification_settings.png

    firewall_notification_email.png

    malicious_file_notification_email.png

  7. On 1/24/2023 at 8:07 PM, Marcos said:

    We are finalizing the service release of Endpoint v10. When released, you can send a software install task to clients to upgrade them to the latest version or wait 2-4 weeks until it upgrades automatically if you have automatic program updates enabled.

    Hi! We have updated our endpoints to v10.2034, but as the days are passing by, we are getting more and more complains from employees about Outlook freezing/lagging. Is there going to be another update/fix?

×
×
  • Create New...