I have yet to see an application contained by ATP Dynamic Application Containment (DAC). Are my polices or rules too relaxed. I have everything configured as McAfee recommended, but I'm not actually seeing where DAC is containing applications. There is nothing in violation event ID 37280. How do I know if the product is working as it should if its not containing anything. Is there a test application/file I can use to demonstrate an applications containment? Any insight would be helpful on this. Thanks.
Hello,
Thank you for your post.
To test the ATP-DAC you need to set the reputation of a file and then run it, so that you can result.
You can easily test it if you have a local TIE server, let us know if you have a TIE server, I will guide you to set the reputation of the file.
I hope this helps.
Let us know if you have any queries.
Yes, I have a TIE server as well. Please provide steps, KB, and/or guide etc. Thanks!
Hello,
Thank you for your reply. Please refer to the below links to know how to set the reputations.
How to change reputation scores in Threat Intelligence Exchange
Technical Articles ID: KB82922
https://kc.mcafee.com/corporate/index?page=content&id=KB82922
How to use the Threat Intelligence Exchange Server "set reputation" remote command with the ePolicy Orchestrator Web API
Technical Articles ID: KB87695
https://kc.mcafee.com/corporate/index?page=content&id=KB87695
Set enterprise reputation for files and certificates
https://docs.mcafee.com/bundle/application-control-8.0.0-product-guide-epolicy-orchestrator/page/GUI...
I hope this helps.
Let us know if you have any queries.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA