- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Detect in Log and Prevent in Report. How can it be...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Detect in Log and Prevent in Report. How can it be?
Hello. I need some help with Threat Emulation. Our customer have a couple of incidents with virus prevention.
A virus file can pass check point with detect in logs:
Matched Rules:
Rules:
Severity - Critical, Confidence Level - High. Threat Prevention profile:
At the same time if we open summury report we see Prevent:
What is wrong? Antivirus does not blok this file too.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Just with a quick glance - Threat prevention profile shows "Standard" and next screenshot profile name is different
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sorry for that, it's just an example. I have not an original screenshots (just for now).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It's all in the details. Actual screenshots showing your real sypmtoms will allow us to help you. Please replace the examples above with your real screenshots.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have updated screenshots
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Did the end user in question actually receive the document?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes. Local antivirus detect it in received email.
Actually I have noticed that our other customer has the same problem.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I could see the Forensics piece saying prevent if AV ultimately caught it (even if TE didn’t).
A TAC case is probably warranted here.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes, I have created TAC case. They are going to organize remote session. I'll share the answer after.
