<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sandblast Agent preventing applications from performing functions in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-preventing-applications-from-performing/m-p/19936#M3587</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I currently have the &lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3d3d3d; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px; word-wrap: break-word;"&gt;Sandblast E80.82 client&lt;/SPAN&gt; installed and when the Forensic, Remediation and Anti-Ransomware is deployed users can not open files in&amp;nbsp;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3d3d3d; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px; word-wrap: break-word;"&gt;QuickBooks &lt;/SPAN&gt;2017.&amp;nbsp; When I uninstall the blade QuickBooks works. Apparently disabling the policy does nothing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are no notifications to the client that Sandblast has performed any action.&lt;/P&gt;&lt;P&gt;The GUI shows cases that occurred at 5:30 AM under analyzed cases or infections and that workstation was not being used at 5:30 AM, even still the Forensic Analysis reports "&lt;SPAN style="color: #000000; font-family: 'Open Sans', 'Segoe UI', Arial; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;These are potentially malicious files that were not remediated."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The log viewer shows that the same TE Event but the "Remediation Action" is Ignore.&lt;/P&gt;&lt;P&gt;SmartLog shows the same entry as Detect not Prevent.&lt;/P&gt;&lt;P&gt;I downloaded a file that I know would trigger a Prevent Action by Forensics Case Analysis and indeed the Action was Prevent and it was logged in SmartLog.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried adding the QuickBooks executables as exclusions to the monitoring and exclusions of&amp;nbsp;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3d3d3d; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px; word-wrap: break-word;"&gt;Forensics&lt;/SPAN&gt;, Remediation and Anti-Ransomware and the folders used by QuickBooks as exclusions to Threat Extraction and Emulation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions on how to resolve this.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 28 Apr 2018 17:06:45 GMT</pubDate>
    <dc:creator>Cliff_Becker</dc:creator>
    <dc:date>2018-04-28T17:06:45Z</dc:date>
    <item>
      <title>Sandblast Agent preventing applications from performing functions</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-preventing-applications-from-performing/m-p/19936#M3587</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I currently have the &lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3d3d3d; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px; word-wrap: break-word;"&gt;Sandblast E80.82 client&lt;/SPAN&gt; installed and when the Forensic, Remediation and Anti-Ransomware is deployed users can not open files in&amp;nbsp;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3d3d3d; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px; word-wrap: break-word;"&gt;QuickBooks &lt;/SPAN&gt;2017.&amp;nbsp; When I uninstall the blade QuickBooks works. Apparently disabling the policy does nothing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are no notifications to the client that Sandblast has performed any action.&lt;/P&gt;&lt;P&gt;The GUI shows cases that occurred at 5:30 AM under analyzed cases or infections and that workstation was not being used at 5:30 AM, even still the Forensic Analysis reports "&lt;SPAN style="color: #000000; font-family: 'Open Sans', 'Segoe UI', Arial; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;"&gt;These are potentially malicious files that were not remediated."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The log viewer shows that the same TE Event but the "Remediation Action" is Ignore.&lt;/P&gt;&lt;P&gt;SmartLog shows the same entry as Detect not Prevent.&lt;/P&gt;&lt;P&gt;I downloaded a file that I know would trigger a Prevent Action by Forensics Case Analysis and indeed the Action was Prevent and it was logged in SmartLog.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried adding the QuickBooks executables as exclusions to the monitoring and exclusions of&amp;nbsp;&lt;SPAN style="display: inline !important; float: none; background-color: transparent; color: #3d3d3d; font-family: Helvetica Neue,Helvetica,Arial,Lucida Grande,sans-serif; font-size: 15px; font-style: normal; font-variant: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: left; text-decoration: none; text-indent: 0px; text-transform: none; -webkit-text-stroke-width: 0px; white-space: normal; word-spacing: 0px; word-wrap: break-word;"&gt;Forensics&lt;/SPAN&gt;, Remediation and Anti-Ransomware and the folders used by QuickBooks as exclusions to Threat Extraction and Emulation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions on how to resolve this.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Apr 2018 17:06:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-preventing-applications-from-performing/m-p/19936#M3587</guid>
      <dc:creator>Cliff_Becker</dc:creator>
      <dc:date>2018-04-28T17:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: Sandblast Agent preventing applications from performing functions</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-preventing-applications-from-performing/m-p/19937#M3588</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try first to uninstall the SAB and replicate the behaviour. If everything is fine install it again and check if it is blocking. Normally you will see something on the logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Charris Lappas&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2018 04:21:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-preventing-applications-from-performing/m-p/19937#M3588</guid>
      <dc:creator>Charris_Lappas</dc:creator>
      <dc:date>2018-05-24T04:21:24Z</dc:date>
    </item>
  </channel>
</rss>

