Really i don't have idea on sandboxing whether it is there in ATD or not. I have shared the event which i received on ESM and which is generated on McAfee ePO
1.Could you help me to provide information that what this event is for !
2. Is it a threat!
3. If it is not a threat then issue of ePO or ATD!
Please help me on this.
Regards,
Ramakant
Thank you Rich
This detection was generated by Advanced Threat Detection and signalled ePO that a threat had been detected but not handled. The threat was triggered by a malware detection. EMS has then collated the threat event and has alerted you to the fact that ATFD detected a Malware threat but was unable to handle it. To further identify what the threat was and if it has affected your organisation you should review the report generated by ATD in the ATD console.
More details about how to view the analysis reports are contained in the Product Guide on page 104
Regards
Rich
McAfee Volunteer Moderator
Business Products
As you told that could be the way but the log is generated by ePO and from SIEM point of view , how to find this threat ?
By this threat name "atd_detected_threat" , i am unable to find details from ATD articles or from any KB articles. Also searched on google and result page is not having the information related to this threat. Also don't have access to ATD. If i would have access then i could check this option as well.
Thanks for your suggestion. Appreciate if you could help me on this threat name issue.
Help me if anyone could guide me for this threat name. What is this event for and the threat details.
Regards,
Ramakant
, if you don't have access to your ATD system at your organisation you will need to escalate it to your ATD Admins at your organisation for review. This is an operational decision which needs to be taken by your organisation, this is not something that product support can assist with, it comes down to how your organisation has implemented ATD.
Hi all,
from my point of understanding the Data Field "Threat Handeled" is also used for threat events from endpoints. For an endpoint this field is important, because the endpoint executes a file and is able or not to handle (remove/clean) the file.
ATD from my point of understanding, when talking about Sec Ops Platform Reference Architecture, is related to "Advanced Analytics". So ATD uses "Common Communication Platform" to communicate with TIE, uses "Contextualized Intelligences" and is a "Data Management" System.
BUT ATD does not enforce anything, so per design, ATD cannot "handle" a threat, it can only detect. 🙂
This is my point of understanding.... 🙂
Cheers
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA