Security Compliance

USB Defender is unable to detect secure thumb drives in SEM

USB Defender is unable to detect secure thumb drives. Possible fix involves updating the rule used to initiate the active responses so that it blocks all USB devices except the authorized ones.

First published date

11/14/2018 9:27 PM

Last published date

2/14/2020 4:07 PM

Overview

This article applies to Security Event Manager (formerly Log & Event Manager).

Windows does not write a log entry when a USB device is attached to a computer. By installing Windows Defender, the application reads the Windows API and detects it as a mass storage device. This will detach it from the computer. If the appropriate signal is not sent from the Windows API, USB Defender will not be able to detach the device.

Product section

Security Event Manager

Resolution

There is one possible workaround but this may cause other issues. The user needs to update the rule used to initiate the active responses so that it blocks all USB devices except the authorized ones.This action may affect detection of other devices such as USB attached printers, keyboards and mouse units.
 

Additional information about USB Defender’s actions can be found in the TNSwind log file in the ContegoSPOP directory on the host machine.
 

  • 32-bit computers - C:\Windows\System32\ContegoSPOP\spop 
  • 64-bit computers - C:\Windows\SysWOW64\ContegoSPOP\spop
  • Linux - /usr/local/contego/ContegoSPOP