Page 1
Dell Endpoint Security Suite Enterprise Advanced Threat Prevention Quick Start Guide v3.4 May 2022 Rev. A01
Page 2
Notes, cautions, and warnings NOTE: A NOTE indicates important information that helps you make better use of your product. CAUTION: A CAUTION indicates either potential damage to hardware or loss of d...
Page 3
Contents Chapter 1: Introduction................................................................................................................. Contact Dell Pro Support for Software....................
Page 4
Introduction Before you perform tasks explained in this guide, the following components must be installed: Endpoint Security Suite Enterprise - refer to Endpoint Security Suite Enterprise Advanced Ins...
Page 5
Get Started This chapter details the recommended steps to begin administering Advanced Threat Prevention. The recommended steps to begin administering Advanced Threat Prevention include the following ...
Page 6
Get Started
Page 7
The following diagram illustrates the Advanced Threat Prevention agent communication process. The following diagram illustrates Dell Server architecture and communication. Get Started
Page 8
Enable BIOS Image Integrity Verification The BIOS Image Integrity Verification policy is enabled by default when the master switch for Advanced Threat Prevention is enabled. For an overview of BIOS Im...
Page 9
If the Enable BIOS Assurance policy is selected in the Management Console, the Cylance tenant validates a BIOS hash on endpoint computers to ensure that the BIOS has not been modified from the Dell fa...
Page 10
Dell Computer Models supported with BIOS Image Integrity Verification Latitude E5570 Precision Workstation 7510 Latitude E7270 Precision Workstation 7710 Latitude E7470 Precision Workstation T3420 Lat...
Page 11
3. View or modify administrator roles in the right pane. 4. Click Save. NOTE: Dell recommends assigning administrator roles at the Group level rather than at the User level. To view, assign, or modify...
Page 12
Policies This chapter details policy management for Advanced Threat Prevention. Enable Advanced Threat Prevention Recommended Policy Settings Commit Policy Modifications For the complete list of Advan...
Page 13
Threats This chapter details how to identify and manage threats encountered in an enterprise environment following the installation of Advanced Threat Prevention. Identify a Threat View Threat Events ...
Page 14
Label Severity Detail Typically this denotes the correlating Memory Protection or Script Control policy outlined was set to Terminate. Memory Violation Warning Indicates that an executable or script w...
Page 15
Options - Provides a way to integrate with Security Information Event Management (SIEM). Certificate - Allows certificate upload. After upload, certificates display on the Global List tab and can be S...
Page 16
review threats found by Execution Control. These were convicted when a user attempted to execute an application and need more urgent attention than dormant files convicted by Background Threat Detecti...
Page 17
Waive - Add a file to the Waived list on a computer. This file is allowed to execute on the computer. Manage Endpoint Advanced Threats To manage a threat identified on a specific computer: 1. In the l...
Page 18
Disconnected Mode Disconnected mode allows a Dell Server to manage Advanced Threat Prevention endpoints without client connection to the Internet or external network. Disconnected mode also allows the...
Page 19
These policies are sent to the Advanced Threat Prevention client only if the Dell Server detects a Disconnected Mode install token, which is prefixed with "DELLAG." Refer to Admin Help for e...
Page 20
Troubleshooting Recover Advanced Threat Prevention Recover Service You will need your backed up certificate to recover Advanced Threat Prevention service. 1. In the left pane of the Management Console...
Page 21
Use this registry setting for testing/debugging only, as this registry setting controls log verbosity for other components, including Encryption and Encryption Management Agent. Compatibility Mode all...