Hey everyone, I'm new here and hoping for some guidance. I'm part of a team migrating a bunch of our legacy internal apps to Azure (a lift-and-shift approach for now). We've recently rolled out CylancePROTECT across the estate, and it's been... noisy.
Our older applications, some classic ASP and a few .NET Framework 4.5 services, keep triggering 'Scripting Host' and 'Injection' alerts in Cylance. From what I can tell, it's their normal behavior—like using `Process.Start()` to call a local utility, or dynamically building SQL strings (I know, I know, but refactoring them all isn't in phase one). These are isolated backend systems with no external exposure.
My problem is two-fold:
1. Our security team is getting alert fatigue, and I'm worried they'll just shut the rules off, which seems risky.
2. I need to provide a realistic timeline and steps for a fix. Is this a classic case of needing to build exclusions? If so, what's the safest way—by file hash, path, or something else?
I'm nervous about just whitelisting things without understanding the risk. Has anyone else gone through this during a cloud migration? Is there a step-by-step process you followed to validate these legacy behaviors and safely tune the EDR? I'd really appreciate any practical advice on how to approach this without creating a blind spot.
One step at a time