Solved! Go to Solution.
Hi J1mX1,
Thank you for contacting us regarding the analysis issue.
We have seen in the past different results between submitting a sample manually with xmode and automatically submitted by another device. The difference is that when submitting a sample using xmode the user would interact with the sample for the ATD to detect.
Note: submitting a sample with xmode the sample is sent to Dynamic Analysis and you mentioned that the sample was detected by GTI Web/URL engine which is the static analysis.
We need the sample's complete result and the support bundle to verify if ATD did not have any issue when it scanned that sample at that specific moment.
I would advise to raise an SR with McAfee ATD Support so we can troubleshoot the issue.
Best regards,
Hi J1mX1,
Thank you for contacting us regarding the analysis issue.
We have seen in the past different results between submitting a sample manually with xmode and automatically submitted by another device. The difference is that when submitting a sample using xmode the user would interact with the sample for the ATD to detect.
Note: submitting a sample with xmode the sample is sent to Dynamic Analysis and you mentioned that the sample was detected by GTI Web/URL engine which is the static analysis.
We need the sample's complete result and the support bundle to verify if ATD did not have any issue when it scanned that sample at that specific moment.
I would advise to raise an SR with McAfee ATD Support so we can troubleshoot the issue.
Best regards,
Yes we have seen effects where the bot did NOT do or click stuff as it should automated. It stopped right after it rated the URL as example and did not detect the rest. But you don't a sandbox for that 😉
The rating was ONLY based on IP-Reputation of the Links in the PDF as example.
But in that case i don't need the ATD Sandbox and only Mcafee Security for Exchange 8.6/Which uses the same DB for 1/100 of the price....
We had a remote session then to proof and it was fixed. It's simplya cat and mouse game but at that point some things where not working as it should and i don't pay an extra 1/10 Million just for somethjing you get free with a regular ENS Suite (Function i mean).
Greeting from Switzerland
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA