- CheckMates
- :
- Products
- :
- Harmony
- :
- Endpoint
- :
- Endpoint threat extraction and emulation issue wit...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Endpoint threat extraction and emulation issue with temp directory
Hello,
We have two programs that sandblast threat extraction and emulation blade seems to be interfering with certain functions. For instance, when using one of these two programs the end user wants to generate a report and download as a .pdf. When initiated it seems the program attempts to start creating the .pdf and then never actually created the .pdf document. We have tested with shutting off blades and determined that it has to do with two things: First is that the endpoint keeps hold of the temp directory so that users cannot access within another program because it will state that the program is already being used by another program, i.e Word, Adobe. The second issue is that we have to turn off emulate files written to the file system and then it will generate the .pdf documents and print just fine. Has anyone else ever experience this? We have whitelisted both programs and processes that seem to run and it makes no difference. Checkpoints solution was to shut off the emulate part but that is a vital part of the endpoint client. Server R77.30, endpoint 80.85.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What was the SR for this, if any?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3-0487456011
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm curious why, if the issue was not resolved, that the case was not reopened?
Also it looks like you were testing this against E80.83 and we're up to E80.88 now in terms of client versions.
Have you tried this with a later version?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The ticket was "resolved" on the checkpoint side by simply having us shut off the file emulation portion of the blade which is not a long term solution. We have moved to 80.85 since that ticket but not 80.88. I will have to test with 80.88 and investigate.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just to confirm, there was a related bug we fixed in E80.88.
If you're still having issues in E80.88 or above, please open a new support ticket so we can investigate.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I had similar issues with E80.87 and outlook temp folder while SBA and Anti-Exploit are running. It looks like the SBA is creating some violations by holding files written to the Temp directory. It was solved by upgrading to E80.87.9201
from E80.87 What's new:
"Resolves a sharing violation issue in Threat Emulation. Resolves scenarios where applications that try to access a file with exclusive access rights fail due to a Threat Emulation inspection of the file. This also resolves the issue to save documents in PDF format."
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you, with the update to machines using the 80.88 version its seems that the issue is resolved.Hopefully when we update the rest of our fleet we will see that the 80.88 client is still the solution.
