<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic data tampering event in enpoint client in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/data-tampering-event-in-enpoint-client/m-p/5252#M3667</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;i am using Total endpoint Security and it shows me the tampering event. What does this means? is it my PC is not secure or its something else....&lt;IMG class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/57937_0-02-06-d7ec10927b2f54bc243161d6f0c2870a10b0a81335df182487121c0bde473a6b_full.jpg" style="width: 620px; height: 297px;" /&gt;me t&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 14 Aug 2017 10:52:02 GMT</pubDate>
    <dc:creator>Sagar_Manandhar</dc:creator>
    <dc:date>2017-08-14T10:52:02Z</dc:date>
    <item>
      <title>data tampering event in enpoint client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/data-tampering-event-in-enpoint-client/m-p/5252#M3667</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi,&lt;/P&gt;&lt;P&gt;i am using Total endpoint Security and it shows me the tampering event. What does this means? is it my PC is not secure or its something else....&lt;IMG class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/57937_0-02-06-d7ec10927b2f54bc243161d6f0c2870a10b0a81335df182487121c0bde473a6b_full.jpg" style="width: 620px; height: 297px;" /&gt;me t&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 10:52:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/data-tampering-event-in-enpoint-client/m-p/5252#M3667</guid>
      <dc:creator>Sagar_Manandhar</dc:creator>
      <dc:date>2017-08-14T10:52:02Z</dc:date>
    </item>
    <item>
      <title>Re: data tampering event in enpoint client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/data-tampering-event-in-enpoint-client/m-p/5253#M3668</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;One of the ways SandBlast Agent monitors for suspicious activity is to track files that were modified (or deleted) by a process that is unusual or unexpected--files that might be tampered with.&lt;/P&gt;&lt;P&gt;On it's own, it's not necessarily an indicator of compromise.&lt;/P&gt;&lt;P&gt;If there are other indicators, compromise is far more likely.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 Aug 2017 16:44:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/data-tampering-event-in-enpoint-client/m-p/5253#M3668</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-08-14T16:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: data tampering event in enpoint client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/data-tampering-event-in-enpoint-client/m-p/5254#M3669</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sir, i cannot find any update regarding the tampering event in my endpoint server . Does these event occur in sandblast is update to server or not. Can i get the report of such event from the endpoint management server and how.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Aug 2017 03:52:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/data-tampering-event-in-enpoint-client/m-p/5254#M3669</guid>
      <dc:creator>Sagar_Manandhar</dc:creator>
      <dc:date>2017-08-17T03:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: data tampering event in enpoint client</title>
      <link>https://community.checkpoint.com/t5/Endpoint/data-tampering-event-in-enpoint-client/m-p/5255#M3670</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; font-size: medium;"&gt;The screen you are showing is part of a forensics report.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; font-size: medium;"&gt;This report is triggered when we identify an attack and it is automatically analyzing the full scope of the attack.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; font-size: medium;"&gt;One of the sections in the report is to identify what is the attack damage. This is listed under the “Business Impact” section. Both in the overview tab and as a separate tab. In this case the attack included the tempering of some files.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000;"&gt;&lt;SPAN style="font-family: Calibri; font-size: medium;"&gt;To see what triggered SBA to say there is an attack, you can look at the trigger data on the top of the overview tab. It will show the “&lt;/SPAN&gt;&lt;SPAN style="font-family: 'Segoe UI',sans-serif; font-size: 10.5pt;"&gt;Trigger:”,&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Calibri; font-size: medium;"&gt; “&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 10.5pt; font-family: 'Segoe UI',sans-serif;"&gt;Triggered By:&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Calibri; font-size: medium;"&gt;” &amp;amp; “&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 10.5pt; font-family: 'Segoe UI',sans-serif;"&gt;Trigger Time:&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: Calibri; font-size: medium;"&gt;” information.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; font-size: medium;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; font-size: medium;"&gt;These reports are available both on the client, and on the server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; font-size: medium;"&gt;On the client it is on the Forensics tab of the client UI.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; font-size: medium;"&gt;On the server, it can be opened by a link on the Forensics log line. You can see it either in SmartLog or in SmartEvent.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; font-size: medium;"&gt;If you want to use SmartEvent you can use &lt;/SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110894&amp;amp;partition=General&amp;amp;product=SmartEvent"&gt;&lt;SPAN style="color: #0000ff; text-decoration: underline; font-size: medium; font-family: Calibri;"&gt;sk110894&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="color: #000000; font-family: Calibri; font-size: medium;"&gt; to see how to connect R80.10 SmartEvent to an R77.30.03 management, and &lt;/SPAN&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk118525"&gt;&lt;SPAN style="color: #0000ff; text-decoration: underline; font-size: medium; font-family: Calibri;"&gt;sk118525&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="color: #000000; font-family: Calibri; font-size: medium;"&gt; to import SAB views to your SmartEvent.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;Thanks&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;Lior Arzi&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Aug 2017 08:56:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/data-tampering-event-in-enpoint-client/m-p/5255#M3670</guid>
      <dc:creator>Lior_Arzi</dc:creator>
      <dc:date>2017-08-17T08:56:15Z</dc:date>
    </item>
  </channel>
</rss>

