zakergfx 0 Posted July 29 Posted July 29 Hello, We would like to start from scratch with our ESET Inspect environment to be sure everything works correctly before being deployed to every endpoint. To do so i disabled all rules except one that i made. This rule simply trigger a detection when powershell is opened on a device. After some tests it works correctly. To test the learning mode feature, i did enable the learning mode on my own computer and simply opened powershell, then disabled the learning mode. While in the last events of my computer i can see that the rule got triggered, i don't see any questions nor exclusions associated to this rule and i don't understand why. From my understanding of the learning mode it should add an exclusion automatically and ask me in the question section if i want to keep this exclusion or not. Thank you for the help.
Recommended Posts