<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sandblast Agent machines got rebooted automatically in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-machines-got-rebooted-automatically/m-p/11280#M3731</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check Point has an AV that comes with some of our endpoint licensing bundles.&lt;/P&gt;&lt;P&gt;We've also tested with some third party AV as well:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116024" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116024"&gt;SandBlast Integration with Third Party Anti-Virus Vendors&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AV and SBA look for different things and operate on different principles.&lt;/P&gt;&lt;P&gt;It's recommended to have both as part of a multi-layer prevention strategy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 30 Mar 2018 23:27:45 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-03-30T23:27:45Z</dc:date>
    <item>
      <title>Sandblast Agent machines got rebooted automatically</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-machines-got-rebooted-automatically/m-p/11277#M3728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recently&amp;nbsp;implemented Endpoint Sandblast Agent for one of my client company where I have faced a challenge&amp;nbsp;after installing Sandblast Agent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Out of some client machines, few machines got rebooted automatically soon after installed sandblast Agent.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no clue why it has rebooted so I decided to uninstall the Sandblast on one machine and though the machine was rebooted. I installed some third party Anti-VIrus(Norton antivirus)&amp;nbsp; and found some bugs on the client machine(which already exist on the machine).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As soon as found the bug I removed and tried to installed SA(Sandblast Agent) once again and till now the machine is not rebooted.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am very surprised the way how the issue got fixed, I tried the same all problematic machines and all are fixed in the same manner.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: Used Sandblast Agent blade: Forensic, Anti-ransomware, extraction and emulation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do anyone have an idea why sandblast Agent has not remediated the existing bugs on the client machine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Arun.R&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 13:08:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-machines-got-rebooted-automatically/m-p/11277#M3728</guid>
      <dc:creator>Arun_R</dc:creator>
      <dc:date>2018-03-30T13:08:09Z</dc:date>
    </item>
    <item>
      <title>Re: Sandblast Agent machines got rebooted automatically</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-machines-got-rebooted-automatically/m-p/11278#M3729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Look at it this way: tools like SandBlast Agent, traditional AV, and malware operate at a similar level in the system.&lt;/P&gt;&lt;P&gt;If the malware was there first, it can potentially block these tools from working (or hide from them).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also keep in mind that SandBlast Agent is specifically looking at files and EXEs entering the machine.&lt;/P&gt;&lt;P&gt;If the malicious files were already there before SBA is installed, it's not going to see them.&lt;/P&gt;&lt;P&gt;This is why SBA should be deployed in conjunction with a traditional Anti-Virus that does periodic scans.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 22:46:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-machines-got-rebooted-automatically/m-p/11278#M3729</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-30T22:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: Sandblast Agent machines got rebooted automatically</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-machines-got-rebooted-automatically/m-p/11279#M3730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks&amp;nbsp;for your update Dameon. Is there is any specific&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;traditional Anti-Virus that we can use on SBA client machine.?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;One more query is that should We need to keep the Anti-Virus software on the client machine even after deploying the SBA on the respective machine.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;- Arun.R&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 23:20:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-machines-got-rebooted-automatically/m-p/11279#M3730</guid>
      <dc:creator>Arun_R</dc:creator>
      <dc:date>2018-03-30T23:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: Sandblast Agent machines got rebooted automatically</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-machines-got-rebooted-automatically/m-p/11280#M3731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check Point has an AV that comes with some of our endpoint licensing bundles.&lt;/P&gt;&lt;P&gt;We've also tested with some third party AV as well:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116024" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116024"&gt;SandBlast Integration with Third Party Anti-Virus Vendors&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;AV and SBA look for different things and operate on different principles.&lt;/P&gt;&lt;P&gt;It's recommended to have both as part of a multi-layer prevention strategy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 23:27:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-machines-got-rebooted-automatically/m-p/11280#M3731</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-30T23:27:45Z</dc:date>
    </item>
    <item>
      <title>Re: Sandblast Agent machines got rebooted automatically</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-machines-got-rebooted-automatically/m-p/11281#M3732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your update on this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Based on the update of your that gave me the impression of Anti-Malware blade in Checkpoint Endpoint Security Management Server license bundles and also some third-party AV vendor(If no Anti-malware been used).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once again thanks for spending your time spends with&amp;nbsp;me on this&amp;nbsp;query, which gave a new experience/lesson for further SBA implementation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Arun.R&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 23:48:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-machines-got-rebooted-automatically/m-p/11281#M3732</guid>
      <dc:creator>Arun_R</dc:creator>
      <dc:date>2018-03-30T23:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: Sandblast Agent machines got rebooted automatically</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-machines-got-rebooted-automatically/m-p/11282#M3733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition to my last update, Is there is any knowledge base quote this " I.e best recommendation/Practice to use AV along with SBA.?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Arun.R&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Mar 2018 23:51:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-machines-got-rebooted-automatically/m-p/11282#M3733</guid>
      <dc:creator>Arun_R</dc:creator>
      <dc:date>2018-03-30T23:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: Sandblast Agent machines got rebooted automatically</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-machines-got-rebooted-automatically/m-p/11283#M3734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The SBA package does not include Anti-malware (AV) but if you buy the Complete package, it is included.&lt;/P&gt;&lt;P&gt;As far as I know, there isn't an SK that says you should deploy both technologies as most customers do this already.&lt;/P&gt;&lt;P&gt;The reason we sell&amp;nbsp;SBA without AV is many customers already have a preferred AV vendor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 Mar 2018 01:40:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-machines-got-rebooted-automatically/m-p/11283#M3734</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-31T01:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: Sandblast Agent machines got rebooted automatically</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-machines-got-rebooted-automatically/m-p/11284#M3735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the update.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It improves my performance in SBA implementation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Once again thanks for your's assist.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-ArunHari.R&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 31 Mar 2018 01:51:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Sandblast-Agent-machines-got-rebooted-automatically/m-p/11284#M3735</guid>
      <dc:creator>Arun_R</dc:creator>
      <dc:date>2018-03-31T01:51:12Z</dc:date>
    </item>
  </channel>
</rss>

