Hi, what is the criteria when an app gets "released from containment"?
Why would an app get contained then only to be released and at the request of ATP? Does the process get re-scanned/evaluated when it is accessed again and the reputation changed on the 2nd scan/evaluation?
The application <some.exe> was released from containment at the request of Adaptive Threat Protection.
Thank you for reaching out McAfee Enterprise Support Community.
Adaptive Threat Protectionuses an application's reputation to determine whether Dynamic Application Containment runs the application with restrictions. Dynamic Application Containment blocks or logs unsafe actions of the application, based on containment rules.
As applications trigger containment block rules, Dynamic Application Containment uses this information to contribute to the overall reputation of contained applications.
Other technologies, such asMcAfee® Active Response, can request containment. If multiple technologies registered with Dynamic Application Containment request to contain an application, each request is cumulative. The application remains contained until all technologies release it. If a technology that has requested containment is disabled or removed, Dynamic Application Containment releases those applications.
Please do check with the work flow in the below mentioned article,
The reputation changes from a TIE server or the app terminates. The reputation will be cached until one of the following 1) JCM cache is cleared 2) TIE server pushes down a new reputation 3) added to Trust dats. If a lookup fails, it will scan again at the next execution, but only if the first instance of the app terminates.
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.
Community Help Hub
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.