I am currently try to test that my ENS On Access scan is working according to the following article.
The first two were successful. Under the section "Test GTI-REST using the Artemis test program" I'm not sure how to verify what actually happened. Should it be in a log file somewhere? Looking at the Event Log in the McAfee Endpoint Security console nothing shows up. The only thing I do get is after running the file I get a dialog box with "Thanks for executing one of the MBL installation check test files. [dirty}." Does this mean success?
I have verified that the computer running the test has a policy for On Access scanning, and the Enable GTI is checked.
Any assistance would be greatly appreciated. Thanks
John
Hello @jbevly Thank you for reaching out McAfee Enterprise Support Community. If we run the third test "Test GTI-REST using the Artemis test program", Did we extarct the file using the password "test_detection" . After we extract Rest-GTI-Artemis-test.exe, We should execute the file to trigger an on-access scan on this file.
The sample contains a test detection that only triggers a detection if GTI File Reputation using REST is enabled and working.
The detection name Artemis!5DB32A316F07 appears in the threat event.
Was my reply helpful?
If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
Hi @jbevly ,
The file gets flagged by On-Access when its extracted.
You may try a right click Scan as well.
Thanks
Was my reply helpful?
If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA