{"id":9085,"date":"2019-10-24T10:21:59","date_gmt":"2019-10-24T08:21:59","guid":{"rendered":"https:\/\/www.boc.de\/watchguard-info-portal\/?p=9085"},"modified":"2019-10-29T14:19:38","modified_gmt":"2019-10-29T13:19:38","slug":"tdr-host-sensor-kernel-driver-settings","status":"publish","type":"post","link":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/2019\/10\/tdr-host-sensor-kernel-driver-settings\/","title":{"rendered":"TDR Host Sensor Kernel Driver Settings"},"content":{"rendered":"<p>WatchGuards Security Service <a href=\"https:\/\/www.boc.de\/watchguard-info-portal\/produktinfos\/watchguard-security-services-und-suites\/watchguard-threat-detection-and-response\/\" target=\"_blank\" rel=\"noopener\">Threat Detection &amp; Response<\/a>\u00a0ist seit \u00fcber 2 Jahren verf\u00fcgbar und wird kontinuierlich weiterentwickelt und verbessert.\u00a0 Um die in TDR verf\u00fcgbaren Funktionen optimal nutzen zu k\u00f6nnen\u00a0empfiehlt WatchGuard dringend, die Host Sensor Kernel Driver Settings auf allen Desktop- und Mobilger\u00e4ten zu aktivieren. Diese Einstellungen sollen einen besseren Schutz sowohl f\u00fcr die tradtionelle Detection- &amp; Response-Funktion als auch f\u00fcr die Host Ransomware Protection erm\u00f6glichen. Seit Dezember 2018 sind diese Einstellungen als Standard f\u00fcr neue Konten festgelegt. Wie Sie die Einstellungen aktiveren k\u00f6nnen:<\/p>\n<p><!--more--><\/p>\n<ol>\n<li>Loggen Sie sich in die TDR Web UI als Administrator oder Analyst ein<\/li>\n<li>unter\u00a0<strong>Settings &gt; Host Sensor<\/strong>.<\/li>\n<li>in den\u00a0<strong>Host Sensor Driver Configuration Settings\u00a0<\/strong>folgende Einstellungen mit\u00a0\u00a0&#8216;<strong>ON&#8217; <\/strong>aktivieren:\n<ul>\n<li>Enable Kernel Process Events<\/li>\n<li>Enable Kernel File Events<\/li>\n<li>Enable Kernel Registry Events<\/li>\n<li>Enable Kernel Kill Process Action<\/li>\n<li>Enable Kernel Delete File Action<\/li>\n<li>Enable Kernel Host Containment Action<\/li>\n<li>Enable Kernel File Handle Enumeration<\/li>\n<\/ul>\n<\/li>\n<li>anschlie\u00dfend speichern mit &#8216;<strong>Save&#8217;<\/strong>.<\/li>\n<\/ol>\n<p>Weitere Informationen zu den empfohlenen TDR-Settings finden Sie im\u00a0<a href=\"https:\/\/www.watchguard.com\/help\/docs\/help-center\/en-US\/Content\/en-US\/Fireware\/services\/tdr\/tdr_deploy_tips_c.html\" target=\"_blank\" rel=\"noopener\">WatchGuard Help Center<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>WatchGuards Security Service Threat Detection &amp; Response\u00a0ist seit \u00fcber 2 Jahren verf\u00fcgbar und wird kontinuierlich weiterentwickelt und verbessert.\u00a0 Um die in TDR verf\u00fcgbaren Funktionen optimal nutzen zu k\u00f6nnen\u00a0empfiehlt WatchGuard dringend, die Host Sensor Kernel Driver Settings auf allen Desktop- und Mobilger\u00e4ten zu aktivieren. Diese Einstellungen sollen einen besseren Schutz sowohl f\u00fcr die tradtionelle Detection- &amp; Response-Funktion als auch f\u00fcr die Host Ransomware Protection erm\u00f6glichen. Seit &hellip; <a href=\"https:\/\/wordpress.boc.de\/watchguard-info-portal\/2019\/10\/tdr-host-sensor-kernel-driver-settings\/\" class=\"more-link\">Weiterlesen <span class=\"screen-reader-text\">TDR Host Sensor Kernel Driver Settings<\/span> <span class=\"meta-nav\">&raquo;<\/span><\/a><\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[445],"tags":[375,593,369,370],"class_list":["post-9085","post","type-post","status-publish","format-standard","hentry","category-aktuelle-nachrichten","tag-host-sensor","tag-host-sensor-kernel-driver","tag-tdr","tag-threat-detection-and-response"],"_links":{"self":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts\/9085"}],"collection":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/comments?post=9085"}],"version-history":[{"count":3,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts\/9085\/revisions"}],"predecessor-version":[{"id":9137,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/posts\/9085\/revisions\/9137"}],"wp:attachment":[{"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/media?parent=9085"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/categories?post=9085"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wordpress.boc.de\/watchguard-info-portal\/wp-json\/wp\/v2\/tags?post=9085"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}