<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prevent malicious files from being written to the file system using SBA in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4631#M3796</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Files have to be downloaded in order to be sent to Cloud or Local Emulation.&lt;/P&gt;&lt;P&gt;I know that SandBlast Agent for Browsers has a control as to whether the files are kept afterwords or not:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116854" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116854"&gt;Where does Threat Extraction SandBlast Agent for Browsers save original files&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 31 Jul 2017 15:55:37 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2017-07-31T15:55:37Z</dc:date>
    <item>
      <title>Prevent malicious files from being written to the file system using SBA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4630#M3795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How can I prevent malicious files from being written to the file system using a Threat Emulation blade of SandBlast Agent?&amp;nbsp;In policies, I can only specify whether to emulate these files or not.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jul 2017 12:06:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4630#M3795</guid>
      <dc:creator>Olga_Kuts</dc:creator>
      <dc:date>2017-07-31T12:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent malicious files from being written to the file system using SBA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4631#M3796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Files have to be downloaded in order to be sent to Cloud or Local Emulation.&lt;/P&gt;&lt;P&gt;I know that SandBlast Agent for Browsers has a control as to whether the files are kept afterwords or not:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116854" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk116854"&gt;Where does Threat Extraction SandBlast Agent for Browsers save original files&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 31 Jul 2017 15:55:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4631#M3796</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-07-31T15:55:37Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent malicious files from being written to the file system using SBA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4632#M3797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; font-size: medium;"&gt;As Dameon wrote, Threat Extraction &amp;amp; Threat Emulation in the SBA browser extension will prevent the malicious files from getting to the disk.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: #000000; font-family: Calibri; font-size: medium;"&gt;SBA browser extension is an integral part of the Sandblast Agent installation you have.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Aug 2017 18:54:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4632#M3797</guid>
      <dc:creator>Lior_Arzi</dc:creator>
      <dc:date>2017-08-03T18:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent malicious files from being written to the file system using SBA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4633#M3798</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I copy the malicious file to the system through USB,what will be the case ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will that file be removed or we can't ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jan 2019 12:09:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4633#M3798</guid>
      <dc:creator>nagaraja_cs</dc:creator>
      <dc:date>2019-01-04T12:09:00Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent malicious files from being written to the file system using SBA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4634#M3799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In this case, the local copy of the file will be removed, but the file on the USB will remain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Gal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jan 2019 12:39:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4634#M3799</guid>
      <dc:creator>Gal_Carmeli</dc:creator>
      <dc:date>2019-01-04T12:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent malicious files from being written to the file system using SBA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4635#M3800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How we can remove the file from the system ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jan 2019 12:57:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4635#M3800</guid>
      <dc:creator>nagaraja_cs</dc:creator>
      <dc:date>2019-01-04T12:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent malicious files from being written to the file system using SBA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4636#M3801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want the file to be deleted from the usb, you need to trigger on the file itself. If you double click the file on the usb drive and the trigger will be directly on that file, it will be deleted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Gal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jan 2019 17:52:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4636#M3801</guid>
      <dc:creator>Gal_Carmeli</dc:creator>
      <dc:date>2019-01-04T17:52:28Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent malicious files from being written to the file system using SBA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4637#M3802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't want to delete the file from the USB.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want it to be deleted from the local PC,how we can delete this malicious file automatically from Sandblast when the verdict is malicious.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Jan 2019 04:54:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4637#M3802</guid>
      <dc:creator>nagaraja_cs</dc:creator>
      <dc:date>2019-01-05T04:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent malicious files from being written to the file system using SBA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4638#M3803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As noted in previous comments, it should not be written&amp;nbsp;to the local system in the first place, so it should not need to be deleted.&lt;/P&gt;&lt;P&gt;Even in the case where the SBA Plugin downloads a file to send it to emulation, it is not done in a user accessible location.&lt;/P&gt;&lt;P&gt;Only if the file is deemed safe it is written to a user accessible location.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Jan 2019 07:24:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/4638#M3803</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-01-05T07:24:12Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent malicious files from being written to the file system using SBA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/107358#M3853</link>
      <description>&lt;P&gt;when you copy a file from USB to the local PC it is automatically sent in parallel to Threat Emulation cloud (TE).&lt;/P&gt;
&lt;P&gt;if TE returns a malicious verdict (between a couple of sec and a couple of min, depends on the scenario), SBA will immediately delete the file.&lt;/P&gt;
&lt;P&gt;SBA does not block the copy itself until the verdict returns. this is in order to provide a smooth user experience as the TE result can take up to a couple of min. the file is accessible immediately and is getting deleted only when a malicious verdict received from TE.&lt;/P&gt;</description>
      <pubDate>Sat, 09 Jan 2021 08:35:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/107358#M3853</guid>
      <dc:creator>Lior_Arzi</dc:creator>
      <dc:date>2021-01-09T08:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent malicious files from being written to the file system using SBA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/129177#M4713</link>
      <description>&lt;P&gt;What are some other vectors from which a file written to the filesystem will be emulated (in parallel) not including downloading with a browser?&lt;/P&gt;&lt;P&gt;Save As attachment from an email in the Desktop Version of Outlook 2013?&lt;/P&gt;&lt;P&gt;Copying files from a file server within the same Active Directory domain to the local PC?&lt;/P&gt;&lt;P&gt;Creating a new Excel Document in the desktop version of Excel 2013 and doing a Save As?&lt;/P&gt;&lt;P&gt;Files written by a backup application like Storage Craft ShadowProtect, backup process running on one server, writing the .bkf file to another server which hosts a local backup file structure, and external backup drives, etc?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Sep 2021 16:48:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/129177#M4713</guid>
      <dc:creator>Chris_Butler</dc:creator>
      <dc:date>2021-09-11T16:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent malicious files from being written to the file system using SBA</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/129184#M4714</link>
      <description>&lt;P&gt;My understanding is, assuming it is a file type we support emulation for, it would apply to all of those.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 11 Sep 2021 20:17:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Prevent-malicious-files-from-being-written-to-the-file-system/m-p/129184#M4714</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-11T20:17:08Z</dc:date>
    </item>
  </channel>
</rss>

