The Local Binary Analysis (BA) Signers whitelist feature allows you to enable or disable BA signers in the local whitelist. Enabling or disabling BA signers allows you to customize the whitelist to work specifically with your local endpoint environment.
Note
Only disabled BA signers can be enabled again.
The Local BA Signers whitelist is a list of trusted company names. Portable Executable (PE) files from the companies in the list are trusted because they are signed by an Authenticode certificate. When a file is received, it is searched. If the company name found in the file matches a name on the whitelist, the file is approved and excluded from further analysis.
This feature also allows you to switch between signer modes. The appliance or sensor has two signer modes, default and insecure. You switch to a mode depending on which whitelist you want to use. If you switch to the default mode, you are choosing to use the standardTrellix BA signers whitelist. If you switch to the insecure mode, you are choosing to use the local BA signers whitelist and the standardTrellix BA signers whitelist.
Note
The default mode for the appliance or sensor is default.
The feature allows you to perform the following actions:
Switch signer modes
View the local whitelist
Enable signers in the local whitelist
Disable signers in the local whitelist
You manage the whitelist in the CLI using the following commands:
signer-whitelist modemode—Switches to a specified mode. See Switching between signer modes using the CLI for information about how to use this command.
show signer-whitelist mode—Displays the current signers mode. See Identifying signer modes using the CLI for information about how to use this command.
show signer-whitelist—Displays all enabled signers in the local BA signers whitelist. See Viewing a local BA signer whitelist using the CLI for information about how to use this command.
signer-whitelist disablesigner—Deletes a signer from the local BA signers whitelist. See Deleting a BA signer from the local whitelist using the CLI for information about how to use this command.
show signer-whitelist disabled—Displays all signers that were deleted from local BA signers whitelist. See Viewing a deleted BA signer using the CLI for information about how to use this command.
signer-whitelist enablesigner—Adds a signer to the local BA signers whitelist. See Adding a BA signer to the local whitelist using the CLI for information about how to use this command.
Use case
A customer receives a false positive message during the analysis of a PE file. An Authenticode signature is also found in the file. The customer wants to whitelist the file because a trusted signature was found. The customer asksTrellix to whitelist the file. The request is denied because the standardTrellix BA signers whitelist is global and the message indicates questionable content. The customer configures the Local BA Signers whitelist feature on a local appliance or sensor. The customer can now enable the file in the local whitelist.
Prerequisites
To manage your local BA signers whitelist, ensure the following prerequisites are met:
Administrator or Analyst access.
An established connection between your appliance and the Internet.