Advanced Threat Protection

 View Only
  • 1.  about ATP threat scan and Auto upload

    Posted Aug 19, 2016 02:24 PM

    Hi,

    Is there anyone here how Symantec ATP scan for threats in Endpoints and in Network?

    Thank you.

    Regards,

    Ravi



  • 2.  RE: about ATP threat scan and Auto upload
    Best Answer

    Posted Aug 22, 2016 10:05 AM

    Network processes the network stream by passing it through various filters and detection engines, such s Vantage (signature-based engine that finds threats in the network stream and Synapse, which is a correlation engine).

    Endpoint gathers info by proxying communications between SEP clients and Symantec by leveraging SEP's Endpoint Detection Reponse (EDR). It uses Insight, Cynic (sandbox), an AV engine, and blacklists/whitelists, and SONAR to deal with malicious activity.