Team, We recently installed ATP in Observe mode on windows servers after which we notice Powershell scripts are getting blocked.
Attached screenshot got some errors noticed in the "EndpointSecurityPlatform_Errors" logs file.
Also i see errors related to Real protect cloud scanner in "ATP Activity logs"
Could someone please help with this?
Thanks in Adavance,
Sabarikumar KB
+91-9148194772
Hi @Sabarikumar ,
ATP in observe mode shouldn't block any scripts. Please refer to the Events tab of Endpoint Security to verify whether it was blocked by ATP or other module.
Alternatively please refer to the "AdaptiveThreatProtection_Activity.log" found in the location below.
C:\ProgramData\McAfee\Endpoint Security\Logs
Please also create a service request with MER logs for further investigation.
https://kc.mcafee.com/corporate/index?page=content&id=KB59385
Thanks
Was my reply helpful?
If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
Hi @Sabarikumar ,
If there are no block events in ATP then we may need deeper investigation.
Please raise a ticket with McAfee tech support for further analysis.
Thanks
Was my reply helpful?
If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA