<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SandBlast Agent Quarantine Manager for Administrators in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Quarantine-Manager-for-Administrators/m-p/202056#M7915</link>
    <description>&lt;P&gt;Hi everyone!&lt;/P&gt;&lt;P&gt;Have the same problem even with newer version. It there any solution of this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 03 Jan 2024 12:45:55 GMT</pubDate>
    <dc:creator>Pavlo</dc:creator>
    <dc:date>2024-01-03T12:45:55Z</dc:date>
    <item>
      <title>SandBlast Agent Quarantine Manager for Administrators</title>
      <link>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Quarantine-Manager-for-Administrators/m-p/172856#M6634</link>
      <description>&lt;P&gt;So I had CP Endpoint flag a file today that has been sitting on our network for the last 20 years (no joke), it's an ancient version of DeltaCopy. In any case, Endpoint moved it into a local folder on my PC. Okay, that's alright but, I have now determined I have no ability to view files that are quarantined. I have disabled the endpoints default images from being able to restore files in Quarantine because I do not trust end users to be able to evaluate whether or not a file is safe (ie. not a false positive).&lt;/P&gt;
&lt;P&gt;However, as an administrator I need some ability to review those files at the local desktop level (pushing them all to a central location is not always possible).&lt;/P&gt;
&lt;P&gt;Does anyone know where the utility is &lt;SPAN class="Menu_Options"&gt;RemediationManagerUI.exe&lt;/SPAN&gt;, since it is not deployed to any endpoint? I need to be able to plop this somewhere on a network drive so that I can review and possible delete or restore flagged files.&lt;/P&gt;
&lt;P&gt;The CP website directs me, " Get the &lt;SPAN class="mc-variable Vars_Other.tp_admin variable"&gt;administrator&lt;/SPAN&gt; utility from the &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk117536" target="_blank" rel="noopener"&gt;release homepage&lt;/A&gt;.", but all that I can find there are monolithic installers. I believe I really only need the remediation utility for the given client version, so which package would contain them? They are all .msi installers. I do not work with .msi installers that often.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2023 18:00:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Quarantine-Manager-for-Administrators/m-p/172856#M6634</guid>
      <dc:creator>Tony_Graham</dc:creator>
      <dc:date>2023-02-27T18:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: SandBlast Agent Quarantine Manager for Administrators</title>
      <link>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Quarantine-Manager-for-Administrators/m-p/172882#M6637</link>
      <description>&lt;P&gt;Hi Tony, &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal/role/supportcenterUser/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=126297" target="_self"&gt;this&lt;/A&gt; should do the trick.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2023 19:44:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Quarantine-Manager-for-Administrators/m-p/172882#M6637</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2023-02-27T19:44:02Z</dc:date>
    </item>
    <item>
      <title>Re: SandBlast Agent Quarantine Manager for Administrators</title>
      <link>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Quarantine-Manager-for-Administrators/m-p/172888#M6638</link>
      <description>&lt;P&gt;First, thanks for the link!&lt;/P&gt;
&lt;P&gt;Unfortunately all the download does is barf an Unhandled exception error.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 537px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19818i3AFB5B85832760D7/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_7e1fae374bf399Tony_Graham_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;If I click continue it brings up an interface that is empty and says Initializing....&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19816iD0252B84DD9A74A0/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;If I click anywhere in the window I get:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19817i54A04F7414404EB8/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;So....yah.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Feb 2023 20:08:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Quarantine-Manager-for-Administrators/m-p/172888#M6638</guid>
      <dc:creator>Tony_Graham</dc:creator>
      <dc:date>2023-02-27T20:08:13Z</dc:date>
    </item>
    <item>
      <title>Re: SandBlast Agent Quarantine Manager for Administrators</title>
      <link>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Quarantine-Manager-for-Administrators/m-p/173080#M6645</link>
      <description>&lt;P&gt;As a follow up on this, I tried using the Infinity Portal&amp;gt;Asset Manager&amp;gt;Right Click&amp;gt;Restore Files from Quarantine but it comes up empty. I am guessing you have to point it at some central repository but it is unclear how this is supposed to function in Portal.&lt;/P&gt;
&lt;P&gt;Can I manually blast the file in Quarantine to clear out the flagged file? At present I have no solution to addressing quarantined files.&lt;/P&gt;
&lt;P&gt;**Update I created a Restore Files push operation, pointed it at C:\Temp. Client machine got a pop-up saying Restore Files needed to happen. So I clicked Restore Files but nothing happened so I suspect it needs to point at a repository that you would configure in Portal. Not really the functionality I need at this point. I need something like the download file that doesn't work. Maybe I will try and create a deployment package that contains 'Restore Files' and copy that file to the target machine.&lt;/P&gt;
&lt;P&gt;Just documenting for others but I was able to create a single policy for this machine in Infinity Portal that allows the machine I am working on to restore files in Quarantine. I pushed policy (also took the liberty of updating the client version to current recommended) and now the RemediationManagerUI.exe is available. The path to it was C:\ProgramData\Checkpoint\Endpoint Security\Installer\Checkpoint\Endpoint Security\Remediation which I do not believe is what is in the current documentation SK. I was able to successfully address the Quarantined file at this point.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Feb 2023 21:51:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Quarantine-Manager-for-Administrators/m-p/173080#M6645</guid>
      <dc:creator>Tony_Graham</dc:creator>
      <dc:date>2023-02-28T21:51:04Z</dc:date>
    </item>
    <item>
      <title>Re: SandBlast Agent Quarantine Manager for Administrators</title>
      <link>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Quarantine-Manager-for-Administrators/m-p/202056#M7915</link>
      <description>&lt;P&gt;Hi everyone!&lt;/P&gt;&lt;P&gt;Have the same problem even with newer version. It there any solution of this issue?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 12:45:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Quarantine-Manager-for-Administrators/m-p/202056#M7915</guid>
      <dc:creator>Pavlo</dc:creator>
      <dc:date>2024-01-03T12:45:55Z</dc:date>
    </item>
    <item>
      <title>Re: SandBlast Agent Quarantine Manager for Administrators</title>
      <link>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Quarantine-Manager-for-Administrators/m-p/202098#M7917</link>
      <description>&lt;P&gt;Hi Tony,&lt;/P&gt;
&lt;P&gt;There are currently three ways to restore a file from quarantine if it was quarantined by EFR or ThreatEmulation blades.&lt;/P&gt;
&lt;P&gt;1. &lt;STRONG&gt;Push operation&lt;/STRONG&gt; in management server. In push operation menu-&amp;gt; Add-&amp;gt;Forensics and Remediation-&amp;gt;File remediation-&amp;gt;Choose the Machine-&amp;gt;Check the "Restore the following files" option-&amp;gt; insert the MD5 or the file path/Incident ID.&lt;/P&gt;
&lt;P&gt;2. &lt;STRONG&gt;RemediationManagementUI&lt;/STRONG&gt;. This tool is deployed with the endpoint under c:\program filesx86\Checkpoint\endpoint Security\Remediation\RemediationManagementUI.exe. This requires that you allow this user the option of restoring the files,&lt;/P&gt;
&lt;P&gt;3. &lt;STRONG&gt;AdminRemediationManagementUI.exe&lt;/STRONG&gt;. This tool is version based so you need to know which version is installed on the machine with the file quarantined and download the correct version.&lt;BR /&gt;The correct version is published in the release notes of each new endpoint version being released.&lt;BR /&gt;You can find a list of Release notes for all the different versions in &lt;A href="https://support.checkpoint.com/results/sk/sk102150" target="_self"&gt;this SK.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;So for example, the tool for E87.52 the Release notes can be found &lt;A href="https://support.checkpoint.com/results/sk/sk181658" target="_self"&gt;here&lt;/A&gt;&amp;nbsp;and under Under the&amp;nbsp;&lt;STRONG&gt;Utilities/Services Downloads &lt;/STRONG&gt;there is a link to download the tool for this specific version.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 16:34:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Quarantine-Manager-for-Administrators/m-p/202098#M7917</guid>
      <dc:creator>toviab</dc:creator>
      <dc:date>2024-01-03T16:34:27Z</dc:date>
    </item>
    <item>
      <title>Re: SandBlast Agent Quarantine Manager for Administrators</title>
      <link>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Quarantine-Manager-for-Administrators/m-p/202100#M7918</link>
      <description>&lt;P&gt;Hi Tony,&amp;nbsp;&lt;BR /&gt;This unhandled exception might be due to the wrong version being used. can you use the correct version as described in my comment above and see if it resolves this issue?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 16:37:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Quarantine-Manager-for-Administrators/m-p/202100#M7918</guid>
      <dc:creator>toviab</dc:creator>
      <dc:date>2024-01-03T16:37:56Z</dc:date>
    </item>
  </channel>
</rss>

