Advanced Threat Protection

 View Only
  • 1.  Auto Remediation

    Posted Sep 19, 2018 07:23 AM

    Does Symantec Endpoint ATP will auto remediate a system when a suspicious activity or file is found on the machine or when a file is detected malicious by Cynic sandbox.

    Will the system get remediate automatically? or the system will get isolated automatically?

    If these featyures are not there, will they come in next releases?



  • 2.  RE: Auto Remediation

    Posted Sep 19, 2018 07:27 AM

    It works once you setup a host integrity and quarantine firewall policy:

    https://www.symantec.com/docs/TECH248959

    You can isolate them and remove from isolation once cleaned. But you need to manually remediate.



  • 3.  RE: Auto Remediation

    Posted Sep 19, 2018 07:39 AM

    We have many custmomers who are asking for automatic remediation as well as isolation, these two features are still not there in ATP, we have to manually blacklist the files and if needed manually click on isolate to disconnect the machine from network, however an automation would have make atp better. Like they did with Cynic submission, is somethink like this is planned in future releases?



  • 4.  RE: Auto Remediation

    Posted Sep 19, 2018 07:46 AM

    Don't know I'm just a customer. Perhaps contact support or your SE.



  • 5.  RE: Auto Remediation
    Best Answer

    Broadcom Employee
    Posted Sep 19, 2018 06:34 PM

    No, there are no automatic remediation options in ATP to isolate a client from the network. We do have plans to implement a feature like this is the future. The next version of ATP will not be called ATP. We have no public announcements at ths time, but as Brian says your sales team may be able to provide you with what we can disclose.