So, we have an enterprise antivirus solution and it's all managed on its own console and we only need to make sure it's deployed and that's enough… In theory.
I recently had a look at the so-called "Trusted Zones" on the console and it turns out that it's been whitelisting a lot of locations that in my mind sound like potential areas to be protected:
- /Library
- /private
- /Users/Shared
- /etc
- /Applications
- ~/Library
and a long etc. that makes me think that we're actually not even using the product.
What's your opinion? Any recommended set of locations that should actually be scanned?
Thanks.
