System Details–
OS: Windows 10 Home
Architecture: 64-bit
Version: 22H2
Build: 19045.4412
CIS Version: 12.2.4.8032
CIS Database: 36780
Issues–
As the title suggests, CIS is ignoring my rules for HIPS and Auto-Containment. For the first issue, HIPS, I’ve (repeatedly) told it to unblock the afflicted files for both “the component(s) shown in ‘Blocked by’ column” and “for all security components”. There are several files this happens to, but two examples are:
“C:\Program Files (x86)\KeyCryptSDK\KeyCrypt64(2).dll”
“C:\Program Files (x86)\MSI\Dragon Center\Dragon Center.exe”
It continues to disregard the fact that they’re unblocked, and they appear in the Blocked Applications list several times a day. I’ve confirmed the files appear in the File List as Trusted, in the HIPS list as Allowed Application, and in the Auto-Containment list as Ignore.
For the second issue, I have created a File Group for an external hard drive containing my game library, and I have added it to HIPS as Allowed Application, and to Auto-Containment as Ignore. The File Group is named ‘Game Libraries’, and the included path is “E:\*”, which to my understanding means that all sub-directories are included. I’ve also added the File Group to the “Do not virtualize access to the specified files/folders” list.
While HIPS doesn’t flag anything on that drive, Auto-Containment consistently snags executables as Untrusted. When they get flagged, I exit them and change the file rating to Trusted, which only works some of the time. Again, multiple files are affected, but two examples are:
“E:\Steam\steamapps\common\habl\habl.exe”
“E:\Steam\steamapps\common\Parabellum\Parabellum\Parabellum.exe”
I’m not necessarily convinced this is a bug per se, as it’s an issue that’s followed me for a few versions of CIS; my guess is that it’s a configuration issue that I’m not seeing. I’m wondering if anyone here has run into this issue before, and with such persistence.
I appreciate any help or insight that might be provided.
EDIT: Since this site won’t let new users attach files, here’s a link to the exported configuration file.
https://drive.proton.me/urls/EQVNKVHNX8#y4JNtC4iINB0