Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
freeman91
Participant

Harmony Endpoint - Malicious files attacks, (Active and Dormant)

Hi,

I need an advice, what is the best practice how to get rid of Active and Dormant logs (files)?
Is it possible to remove them?
For example, one of the Active attack is file named add209cc-0fb9-4a38-9450-ee66a961af49.tmp

Protection Name: Gen.Rep.
Protection Type: Offline Reputation
File Type: tmp
 

And, what under Forensics Details ->

Remediated Files: svchost.exe(Termination disabled in policy), {add209cc-0fb9-4a38-9450-ee66a961af49}.tmp(Deleted before) mean? Shoul I enable it?
 
1 Reply
CheckBoy
Explorer

have the same question. How can an Active Attack be acknowledged in Cloud Endpoint? Is it possible?

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 11 Jul 2024 @ 10:00 AM (BST)

    CheckMates Live London

    Tue 30 Jul 2024 @ 05:00 PM (CEST)

    Under the Hood: CloudGuard Controller Unleashed

    Thu 11 Jul 2024 @ 10:00 AM (BST)

    CheckMates Live London
    CheckMates Events