Knowledge Center

Content rule ID 6015 is triggered, even if the Exploit Prevention policy for this rule is disabled
Technical Articles ID:   KB90074
Last Modified:  9/30/2019


McAfee Endpoint Security (ENS) Threat Prevention 10.5.3
McAfee ePolicy Orchestrator (ePO) 5.x
McAfee ePO Cloud


The Status for Content rule ID 6015 is Disabled in the Exploit Prevention policy, but rule ID 6015 is being triggered by Exploit Prevention. This event is a report-only event.

Also, if Event ID: 18055 is selected in Event Filtering, Event ID: 18055 is reported to ePO, and Event ID: 18055 is displayed in the Threat Event Log.


This issue was originally resolved in Endpoint Security 10.5.3 Hotfix 2. Technical Support recommends that you install Endpoint Security 10.5.3 Hotfix 3, which is the latest rollup hotfix, and includes the fixes from the following releases:
  • Endpoint Security 10.5.3 Hotfix 2
  • Endpoint Security 10.5.3 Hotfix 1
Contact Technical Support to obtain the hotfix.


You can safely ignore Content rule ID 6015 when it is disabled in the Exploit Prevention policy.

Rate this document


This article is available in the following languages:

English United States

Glossary of Technical Terms

 Highlight Glossary Terms

Please take a moment to browse our Glossary of Technical Terms.