Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
bund
Explorer

How do I know if a file is dropped? 'Threat Emulation'

Hi 

 

How do I know if a file is dropped in Threat Emulation?

 

Only Log? and ted.log*? 

 

Aren't there any way?

Log.jpg

 

0 Kudos
5 Replies
G_W_Albrecht
Legend Legend
Legend

There is a report in Logs & Monitor, see sk120357: New Threat Emulation reports:

The report now contains also information for archive files descendants, as well as embedded files and dropped files.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
PhoneBoy
Admin
Admin

If anything was dropped, the log card would have said Prevent instead of Detect (upper left corner).

0 Kudos
bund
Explorer

Thank you.
Does this work the same way when in 'Hold mode'?
Is it just detected?
Why is it confirmed as a 'dropped file'?

0 Kudos
Chris_Atkinson
Employee Employee
Employee

To be clear Malware dropping files on an endpoint is a very different context to a log indicating that it is dropping or blocking traffic.

Hold mode is more secure.

Detect here could also be due to the 'low' confidence rating again depending on your TP profile settings.

 

CCSM R77/R80/ELITE
0 Kudos
PhoneBoy
Admin
Admin

By default, none of our default profiles will Prevent for protections with a Confidence Level of Low.

image.png

The "dropped file" refers to what happened when the file in question was emulated.
Specifically, an EXE was created and there was an attempt made to execute it.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events