<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forensics report with 3rd party AV in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Forensics-report-with-3rd-party-AV/m-p/25611#M3559</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The difference is: one is reading from the Windows Event Log, another is relying on being explicitly triggered by the external tool.&lt;/P&gt;&lt;P&gt;As was suggested in the SK, you may need to open a TAC case with the requested information for Troubleshooting.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 11 Sep 2018 13:30:59 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-09-11T13:30:59Z</dc:date>
    <item>
      <title>Forensics report with 3rd party AV</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Forensics-report-with-3rd-party-AV/m-p/25608#M3556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you please direct to a step by step guide on how to configure the Forensics report with 3rd party AV?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have reviewed the&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105122" title="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk105122"&gt;How to configure Forensics blade to analyze an incident that was detected by external system&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but is a bit confusing.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Charris Lappas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2018 17:37:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Forensics-report-with-3rd-party-AV/m-p/25608#M3556</guid>
      <dc:creator>Charris_Lappas</dc:creator>
      <dc:date>2018-09-10T17:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: Forensics report with 3rd party AV</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Forensics-report-with-3rd-party-AV/m-p/25609#M3557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The SK you linked is the tool that would be run to kick off a forensics report, with a few different methods for kicking it off.&lt;/P&gt;&lt;P&gt;As each third party AV is different, the exact instructions&amp;nbsp;will depend on the third party AV in question.&lt;/P&gt;&lt;P&gt;The SK mentions Symantec specifically, there is another SK for Trend:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112436" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk112436"&gt;Setting up Sandblast Agent (SBA) Forensics Analysis trigger from Trend Micro Control Manager&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Sep 2018 22:10:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Forensics-report-with-3rd-party-AV/m-p/25609#M3557</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-10T22:10:07Z</dc:date>
    </item>
    <item>
      <title>Re: Forensics report with 3rd party AV</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Forensics-report-with-3rd-party-AV/m-p/25610#M3558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looking it further there is another SK&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116024&amp;amp;partition=General&amp;amp;product=SandBlast" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116024&amp;amp;partition=General&amp;amp;product=SandBlast"&gt;SandBlast Agent Integration with Third Party Anti-Virus Vendors&lt;/A&gt;&amp;nbsp; so what is the difference between the two. I have followed this SK but the forensics reports are not generated.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2018 09:46:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Forensics-report-with-3rd-party-AV/m-p/25610#M3558</guid>
      <dc:creator>Charris_Lappas</dc:creator>
      <dc:date>2018-09-11T09:46:09Z</dc:date>
    </item>
    <item>
      <title>Re: Forensics report with 3rd party AV</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Forensics-report-with-3rd-party-AV/m-p/25611#M3559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The difference is: one is reading from the Windows Event Log, another is relying on being explicitly triggered by the external tool.&lt;/P&gt;&lt;P&gt;As was suggested in the SK, you may need to open a TAC case with the requested information for Troubleshooting.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2018 13:30:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Forensics-report-with-3rd-party-AV/m-p/25611#M3559</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-11T13:30:59Z</dc:date>
    </item>
  </channel>
</rss>

