Endpoint Protection

 View Only
  • 1.  How to test 'Download Insight' for SEP 12.1 RU2

    Posted Dec 12, 2014 10:51 AM

    I'm trying to trigger an alert from Download Insight, but when i'm downloading .exe files from client computers it doesn't say anything! I read i could use the Cloudcar.exe file but it's not available anymore. Client users need to be aware of the reputation of files they download. How can i trigger an alert for users? 

     I'm using: 

     

    • SEP manager 12.1 RU2 on a Windows server 2008  (with latest updates).
    • SEP12.1 RU2  client on a Windows 7 32bit operating system.
    • Download Insight enabled. To trigger an alert i have set the download sensitivity level to 9 (maximum)
    • Checked files with 5 or fewer users and files know by users for 14 of fewer days
    • I unchecked Automaticaly trust any file downloaded from an intranet website.
    • The action it should take for Malicious files: first action Quarantine risk, if first action fails Leave alone (log only). For unproven files the action is set to Prompt. 

     

    What am i doing wrong? 

     

    Thanks a lot! 



  • 2.  RE: How to test 'Download Insight' for SEP 12.1 RU2
    Best Answer

    Posted Dec 12, 2014 10:55 AM

    Please download the cloudcar file HERE

    I have an article here on it as well:

    How to test SEP 12.1 components for functionality

    In the policy, just select the notification:

    Capture_53.JPG



  • 3.  RE: How to test 'Download Insight' for SEP 12.1 RU2

    Broadcom Employee
    Posted Dec 12, 2014 10:56 AM

    Hi,

    Scanning features in Symantec Endpoint Protection leverage Insight to make decisions about files and applications. Virus and Spyware Protection includes a feature that is called Download Insight. Download Insight relies on reputation information to make detections. If you disable Insight lookups, Download Insight runs but cannot make detections. Other protection features, such as Insight Lookup and SONAR, use reputation information to make detections; however, those features can use other technologies to make detection

    Refer these articles:

    Managing Download Insight detections

    http://www.symantec.com/docs/HOWTO55252

    Customizing Download Insight settings
     


  • 4.  RE: How to test 'Download Insight' for SEP 12.1 RU2

    Posted Dec 12, 2014 11:04 AM

    Thank you all for helping me out so quick! With the Cloudcar.exe file from .Brian i was able to trigger an alert!



  • 5.  RE: How to test 'Download Insight' for SEP 12.1 RU2

    Posted Dec 12, 2014 11:06 AM

    Great :)

    Take care