Risky action Blocked - ASR

Started by scottduk, November 15, 2022, 07:13:26 AM

I have been noticing many alerts on our endpoints for PatchMyPC-ScriptRunner.exe, please see below screenshot.

Do i need to amend something or add some exclusions for AV or ASR ?


Screenshot 2022-11-15 141052.png

Jake Shackelford (Patch My PC)

I would suggest adding an exclusion to that particular EXE to start. You may need to explore allowing exclusions on other folders related to content distribution within ConfigMgr but I would start solely with the ScriptRunner.exe. Depending on the security tool it can detect as a false positive just do to the nature of the exe running in the system context.