cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Highlighted
Level 9
Report Inappropriate Content
Message 1 of 4

Hi all,

i just want to ask why mcafee enstp and ATP only /would block and block the malwares ? (in my case its lemonduck, monero), why mcafee can't "stop" block at early stage (user action ex click attachment or links) and is "Dropper.bat" hidden/filess type of file? because from the looks of it mcafee blocking start on "powershell" stage,

at the moment we have serious issue in our DB servers, we installed atp but beside Blocking event we crosscheck with forti that sql/db server still trying to "brute force the sql server/DB server for login" and also keeps trying sending data to the outside of our area (out of country by the ip types)

in this mcafee blog : https://www.mcafee.com/blogs/other-blogs/mcafee-labs/mcafee-amsi-integration-protects-against-malici... 

atp killchainatp killchain

1 Solution

Accepted Solutions
Highlighted
Level 10
Report Inappropriate Content
Message 4 of 4

Re: ENS ATP

Jump to solution

Hi,

In my experience relying on the Antivirus to do all the security jobs is the first mistake. When it is about SMB the operating system patches should all be installed and all the OS in the network must be up to date otherwise the Antivirus cannot do anything about it, I have seen it several times in different Antivirus software which have been totally unable to defend the vulnerable OS. Plus that resetting the admin password after being infected is one of the very first steps, so please do as Support says.

Also regarding the ATP please make sure that the Block action is selected for the rules you believe are needed to be blocked.

Good luck and please do not wait, you need to act as fast as you can!

View solution in original post

3 Replies
Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 4

Re: ENS ATP

Jump to solution

@Dwee 
ENSTP can detect files at early stage if these are known as malicious. ATP is effective if file are NOT known as malicious. ENSTP can't detect unknown files or fileless malware, so ENS ATP monitors and blocks their behavior at later stage. Therefore, if a dropper.bat is known as malicious, ENSTP will detect it. In the case that it is unknown, ENS ATP will monitor and block it's behavior. I think the blog article explains later case.

Was my reply helpful?

If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Highlighted
Level 9
Report Inappropriate Content
Message 3 of 4

Re: ENS ATP

Jump to solution

Hi, thx for your reply,

the thing is our customer doesnt case want only block, they want "clean,delete,quarantie", and also want mcafee to give some solid "white paper analysis report" about "mcafee delete / kill " lemonduck and other malware, and the funny is that in their network ther smb still open and exploited through there to get login /account admin to spread the script, can our ens tp and atp prevent that hole in their enviromnet? the support said we need to reset the ad admin password user, but that will have major impact on our dev server environment (that already compromised), do wee need to reset password first ?

regards,

Dwi

Highlighted
Level 10
Report Inappropriate Content
Message 4 of 4

Re: ENS ATP

Jump to solution

Hi,

In my experience relying on the Antivirus to do all the security jobs is the first mistake. When it is about SMB the operating system patches should all be installed and all the OS in the network must be up to date otherwise the Antivirus cannot do anything about it, I have seen it several times in different Antivirus software which have been totally unable to defend the vulnerable OS. Plus that resetting the admin password after being infected is one of the very first steps, so please do as Support says.

Also regarding the ATP please make sure that the Block action is selected for the rules you believe are needed to be blocked.

Good luck and please do not wait, you need to act as fast as you can!

View solution in original post

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community