Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
bund
Contributor

How do I know if a file is dropped? 'Threat Emulation'

Hi 

 

How do I know if a file is dropped in Threat Emulation?

 

Only Log? and ted.log*? 

 

Aren't there any way?

Log.jpg

 

5 Replies
G_W_Albrecht
Legend Legend
Legend

There is a report in Logs & Monitor, see sk120357: New Threat Emulation reports:

The report now contains also information for archive files descendants, as well as embedded files and dropped files.

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
PhoneBoy
Admin
Admin

If anything was dropped, the log card would have said Prevent instead of Detect (upper left corner).

bund
Contributor

Thank you.
Does this work the same way when in 'Hold mode'?
Is it just detected?
Why is it confirmed as a 'dropped file'?

Chris_Atkinson
Employee Employee
Employee

To be clear Malware dropping files on an endpoint is a very different context to a log indicating that it is dropping or blocking traffic.

Hold mode is more secure.

Detect here could also be due to the 'low' confidence rating again depending on your TP profile settings.

 

CCSM R77/R80/ELITE
PhoneBoy
Admin
Admin

By default, none of our default profiles will Prevent for protections with a Confidence Level of Low.

image.png

The "dropped file" refers to what happened when the file in question was emulated.
Specifically, an EXE was created and there was an attempt made to execute it.

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events