Page 1 of 1

Cylance & PoSh Scripts

Posted: Tue Aug 11, 2020 5:22 pm
by sirkerry
Cylance is killing the PoSh scripts from Habitat that run on workstations, any chance y'all can change these over to signed scripts so we can have Cylance whitelist them?

Re: Cylance & PoSh Scripts

Posted: Thu Aug 13, 2020 1:42 pm
by Cubert
I don't know enough about cert signing to just go off and do that.

What little I do know says for that to work I would need a public cert which would need to be purchased and incorporated in to scripts. I will look in to what it takes to do this.

Re: Cylance & PoSh Scripts

Posted: Mon Aug 17, 2020 8:45 pm
by sirkerry
Apparently a way around this is to have the PowerShell script as a .ps1 file in the LTshare instead of creating it on the fly by the script, then it's possible to check the checksum/hash of the .ps1 file against what is on the LTshare that Cylance knows about and have it allow the PoSh script to run (or so I've been told).