So i was told by McAfee Support that the only way i can look at the actual file path of a file/IP/Hostname etc. that was uploaded into ATD is if it was uploaded via other products such as NSM, TIE, and etc.

When we upload let's say a whole File Share drive manually via WinSCP, we cannot look at any of that information.

So our File Share has over 10k sub folders and if ATD picks up anything malicious, how do i locate it? Considering the fact that over 500 users use that file share.

Thanks for your help in advance.

