Jump to content

harryboyne

Members
  • Content Count

    2
  • Joined

  • Last visited

  • Days Won

    1

harryboyne last won the day on March 25

harryboyne had the most liked content!

Community Reputation

2 Neutral

My Information

  • Agent Count
    1000+
  1. Hi All, Following an update to 1809, we have had issues with definitions for any Windows 10 machine with Intune (or just the vanilla Windows Defender). Turns out the 'RemediationEXE' referenced by the LT default definition no longer exists. I create the below definition which seems to work fine - thought I'd share with you all! 😀 Name: Windows Defender 10 AV Process: msmpeng* Program Location: {%_if|{%_ne|{%-HKLM\SOFTWARE\Microsoft\Windows Defender:DisableAntiVirus-%}|1_%}|{%-HKLM\SOFTWARE\Microsoft\Windows Defender:InstallLocation-%}MsMpEng.exe_%} Definition Location: {%-HKLM\SOFTWARE\Microsoft\Windows Defender\Signature Updates:SignatureLocation-%}\mpavdlta.vdm Date Mask: (.*) Update Command: "{%-HKLM\SOFTWARE\Microsoft\Windows Defender:InstallLocation-%}\mpcmdrun.exe" -SignatureUpdate -Trace -Grouping 15 -GetFiles
  2. Hi All, Just wondering if any of you logged a ticket with either ConnectWise or BitDefender regarding this issue - they are claiming ignorance but it's clearly a long standing issue! Thanks
  3. Hi Guys We're looking at rolling out some form of monitor to log a ticket when a server reboots. Usually we'll just close the ticket, but it's a good "FYI" ticket for us to have - in case something's up etc. I've tried creating an "uptime is less than 15" monitor, but we found that it then closed the ticket as soon as it no longer met the requirements: So it's looking like the best way is to monitor for event 6006 (logged when a Windows PC reboots). This does seem a bit messy though and removes some control - we'd like for the monitor to not run during maintenance windows, but if we do with an event log monitor it will just log the ticket after the window! Screenshots are attached of both queries. I was wondering if anyone has already done this and if so has any suggestions? Thanks
×