cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
JKBH1
Level 10
Report Inappropriate Content
Message 1 of 3

ATP requested app to release from containment

Hi, what is the criteria when an app gets "released from containment"?

Why would an app get contained then only to be released and at the request of ATP? Does the process get re-scanned/evaluated when it is accessed again and the reputation changed on the 2nd scan/evaluation? 

Description:

The application <some.exe> was released from containment at the request of Adaptive Threat Protection.

Event Category:Event ID:Threat Severity:Threat Name:Threat Type:Action Taken:Threat Handled:Analyzer Detection Method:

'Process' class or access
37276
Warning
DAC:Released
Dynamic Application Containment
Released from containment
True
Dynamic Application Containment
2 Replies
Sivakumar1
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 3

Re: ATP requested app to release from containment

Hello @JKBH1 ,

Thank you for reaching out McAfee Enterprise Support Community. 

Adaptive Threat Protection uses an application's reputation to determine whether Dynamic Application Containment runs the application with restrictions. Dynamic Application Containment blocks or logs unsafe actions of the application, based on containment rules.

As applications trigger containment block rules, Dynamic Application Containment uses this information to contribute to the overall reputation of contained applications.

Other technologies, such as McAfee® Active Response, can request containment. If multiple technologies registered with Dynamic Application Containment request to contain an application, each request is cumulative. The application remains contained until all technologies release it. If a technology that has requested containment is disabled or removed, Dynamic Application Containment releases those applications.

Please do check with the work flow in the below mentioned article,

https://docs.trellix.com/bundle/endpoint-security-10.6.0-adaptive-threat-protection-product-guide-wi...

Was my reply helpful?
If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!

Re: ATP requested app to release from containment

The reputation changes from a TIE server or the app terminates. The reputation will be cached until one of the following 1) JCM cache is cleared 2) TIE server pushes down a new reputation 3) added to Trust dats.  If a lookup fails, it will scan again at the next execution, but only if the first instance of the app terminates. 

Dave

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community