Endpoint Protection

 View Only
  • 1.  File creation date within Risk Report

    Posted Sep 18, 2016 09:24 AM

    Hello,

    A quarantined malware shows up in the SEP Client console under 'View Quarantine', wherein, it shows the 'File Create Date'.

    Is that the actual creation date of the file OR the date when it landed on the system.

    1. Does it get featured in any of the SEPM Reports?

     

    We need to find out whether the malware was sourced from any remote endpoint. Since source IP field shows value as 0.0.0.0, we need to ascertain whether requirements to retrieve this information in Risk Logs are met.

    2. Will enabling Risk Tracer, Firewall and IPS fulfil the requirement? OR is there something left out?

     

    Thanks,

    Jimmy

    =-=-=

     

     



  • 2.  RE: File creation date within Risk Report

    Posted Sep 18, 2016 09:35 AM

    The file create date should be the time the file was "actioned" by SEP.

    Enabling Risk Tracer will help to the remote source, if available.

    How to use Risk Tracer to locate the source of a threat in Symantec Endpoint Protection

    This info should be in the Risk log on the Monitors tab,.



  • 3.  RE: File creation date within Risk Report

    Posted Sep 19, 2016 09:47 AM

    Hi Brian,

    On a system, I could see that the actioned date was different than the FIle Create date.

    The File Create date seems to be date, on which, the file lands on the system because, in my case, the column "DATE" matches the actioned timestamp, and column "File Create Date" shows an older date.

    -Jimmy

    =-=-=



  • 4.  RE: File creation date within Risk Report

    Posted Sep 19, 2016 03:59 PM

    The Summary page on the SEPM does not show "Risk Distribution by Attacker". It does show Risk Distribution, RIsk Distribution by Group, RIsk Distribution by Source, SONAR, and New Risks.

    Is there any additional configuration, which needs to be done?

     

    -Jimmy

    =-=-=



  • 5.  RE: File creation date within Risk Report

    Posted Sep 19, 2016 04:06 PM

    This tab is not configurable.

    You can find that on the Reports page >> Quick Reports. There are various reports for the "Risk" report type.



  • 6.  RE: File creation date within Risk Report

    Posted Sep 19, 2016 06:48 PM

    Some viruses can change the file creation date, so when you look at when a file that was created it could be for example created 1 year ago when in all actuallity it was created today.

     

    Another good report to use is:

    Sonar Suspeciouse Report:

    Monitors, Logs, and chooses to view a SONAR report with the Advanced filter set to display only the Events where the action resulted in a verdict of "Suspicious."

     

    Yes please use Risk Tracer and install all required features of the product for this to function correctly. 



  • 7.  RE: File creation date within Risk Report

    Posted Sep 20, 2016 12:16 PM

    Possibly a new variant that needs to be submited for signature creation and detection

    Upload a suspected infected file (Essential)

     

    Use the form below to upload a suspected infected file or an email with a malicious attachment to Symantec Security Response.

    This submission form is intended for Essential customers with a valid support ID number.

    Users of Norton products may submit suspicious files to Security Response by using this submission form instead.

    If you are submitting a file you believe to be clean, please use this submission form.

     

    https://submit.symantec.com/websubmit/essential.cgi

     



  • 8.  RE: File creation date within Risk Report

    Posted Sep 22, 2016 05:43 AM

    Thank you for responding!

    Since we know that Auto-Protect and Scheduled Full scans detect and quarantine the malware, it is the Risk Report that we expect to show up the information. But, unfortunately, the information is not found.

    Without such a report, one has to keep guessing on which systems the file could possibly be, making investigations difficult.

     

    Regards,

    Jimmy

    =-=-=



  • 9.  RE: File creation date within Risk Report

    Posted Sep 26, 2016 02:34 AM

    Hi Kimberly,

    Our concern is only about known malware files that are actioned by the SEP Client.

    So we wish to know which report in SEPM shows the information provided by the column 'File Create Date' within the SEP Client console.


    Thanks,

    Jimmy

    =-=-=