Security Compliance
USB devices do not detach with USB Defender (SEM)
Refer to this page if a SEM rule fired to alert you of a USB device attachment, but the USB device was not detached as it should have been.
First published date
Last published date
Overview
Product section
Cause
- Your rule may not be configured with a Detach USB Device action.
- No Windows Active Response connector is configured or running for that agent.
Resolution
Verify that the rule that sent the alert also tried to detach the device:
- On the SEM console menu bar, navigate to Explore > nDepth.
- Conduct a search for the following condition during the time frame of the email alert you received: InternalRuleFired.EventInfo=*USB*
- Find the rule fired event that should have detached the device and highlight it.
- From the Explore drop-down list on the top-right corner, and then choose Event.
- Verify that there is an InternalCommands event listed that has "Initiated Action: Detach USB Device" for the EventInfo.
Verify that there is a Windows Active Response connector configured for the affected agent:
SEM HTML5 console
- In the SEM Events Console, click the Nodes tab.
- Select the agent node, and then click Manage node connectors.
- Under Configured connectors, locate the Windows Active Response connector, and then make sure it is an active connector with a green icon. If it doesn't have a green icon, select it, and then click Start.
- If it is not under Configured connectors, enter Windows Active Response in the search box, and then configure the connector.
SEM Flash console
- On the SEM console menu bar, navigate to Manage > Nodes.
- Locate the agent in question, click its gear icon, and then select Connectors.
- Search for the Windows Active Response connector, and then make sure you have an active connector with a green icon. If you do not, click on the gear next to it and create a new one.
Verify the Detach Unauthorized USB Device rule has the correct settings. It should appear as below:
SEM HTML5 console
SEM Flash console