Long Arrow Right External Link angle-right Search Times Spinner angle-left

Ringfencing Application Interaction

View in Browser

Ringfencing enables you to decide what applications a program can or cannot interact with. This will help eliminate the possibility that a threat actor can use a good application in a malicious way. It is a good idea to block interaction with the powerful built-in Windows tools that you know an application doesn't need access to.   

The following screenshot is from the ThreatLocker default Microsoft Office policy. You can see it is denying Office access to PowerShell, Command Prompt, CScript, RegSVR32, Forfiles, and Scheduled Tasks. 

undefined

Fileless malware is malware that runs strictly in memory. It is often a PowerShell script that has been hidden in a legitimate-looking file, like a Word document for example. If you were to receive a Word document that tried to call on PowerShell to carry out malicious activity, it would not be able to access PowerShell because this Ringfencing policy blocks Microsoft Office from interacting with PowerShell.

ThreatLocker recommends implementing our suggested Ringfencing policies for any application you use that we provide suggested Ringfencing policies for.

Navigate to Application Control > Policies. Select the 'Add Suggested Policies' button at the top of the page.  

undefined

Select the checkbox next to any application you are currently using and then click the 'Add Suggested Policies' button at the top of the page.

undefined

If there is no suggested policy and you are unsure of what your application may need to interact with, we suggest setting your Ringfencing policy in a 'monitor' status for a week to allow you the opportunity to observe the application's behavior and add in any exclusions you will need to this policy without causing work blocks for you users.

undefined

Monitor the activity in the Unified Audit for a week or so to see what exclusions you need to add to your Ringfenced policy before you switch it to 'Secured' status. Set your start and end date for your specified time period. Then, input the name of the policy you are observing the Ringfencing on in the 'Policy Name' text box, and select 'Ringfenced' in the 'Action' dropdown before clicking the 'Search' button. This will quickly show you all the Ringfenced activity for that specific policy. With those search results, you can easily go down the audit list and add these exceptions into the policy by expanding each entry and clicking 'Add to Policy'. 

undefined

Ringfencing - File Access

Ringfencing - Internet Access

Ringfencing -Registry Activity