Reference Guide
Security Management Server Virtual v10.2.11 AdminHelp
trying to read valid magnetic stripe track data from
another process. Typically related to point
-of-sale
systems (POS).
The Scanner Memory Search exploitation affects Windows
op
erating systems. This policy does not apply to Mac
clients.
Exploitation:
Malicious
Payload
Alert
Ignore
Alert
Block
Terminate
Specify the action to take when a malicious payload is
detected.
Ignore
- No action is taken against identified memory
violation
s.
Alert
- Record the violation and report the incident to
the Dell Server.
Block
- Block the process call if an application attempts
to call a memory violation process. The application that
made the call is allowed to continue to run.
Terminate
- Block the process call if an application
attempts to call a memory violation process and terminate
the application that made the call.
Malicious Payload
- A generic shellcode and payload
detection associated with exploitation has been detected.
The Malicious Paylo
ad exploitation affects Windows
operating systems. This policy does not apply to Mac
clients.
Process
Injection:
Remote
Allocation of
Memory
Alert
Ignore
Alert
Block
Terminate
Specify the action to take when a remote memory allocation
threat is detected.
Ignore
- No action is taken against identified memory
violations.
Alert
- Record the violation and report the incident to
the Dell Server.
Block
- Block the process call if an application attempts
to call a memory violation process. The application that
ma
de the call is allowed to continue to run.
Terminate
- Block the process call if an application
attempts to call a memory violation process and terminate
the application that made the call.
Remote Allocation of Memory
- A process has allocated
memory in an
other process. Most allocations will only
occur within the same process. This generally indicates an
attempt to inject code or data into another process, which
may be a first step in reinforcing a malicious presence on
a system.
The Remote Allocation of Me
mory process injection affects
Windows and macOS operating systems.
195