Hi There,
One of my customers is doing POC testing on their Linux systems. they found after ENS for Linux installed, the EICAR test file cant be detected and deleted.
ENSLTP 10.6.5 + Agent 5.6.2 + CentOS 7.2 + Fresh Installation
Belows are some details:
1. Versions:
/opt/isec/ens/threatprevention/bin/isecav --version
McAfee Endpoint Security for Linux Threat Prevention
Version : 10.6.5.107
License : Full
DAT Version : 9368.0
DAT Date : 02-09-2019
Engine Version : 6010.8670
2. ENSLTP service status is OK:
/opt/isec/ens/threatprevention/bin/isectpdControl.sh status
* isectpd.service - McAfee Endpoint Security for Linux Threat Prevention
Loaded: loaded (/usr/lib/systemd/system/isectpd.service; enabled; vendor preset: disabled)
Active: active (running) since Thu 2019-12-05 17:19:27 CST; 25min ago
Docs: man:isectpd(8)
Process: 6683 ExecStartPre=/opt/isec/ens/threatprevention/bin/cgroupMountHelper.sh systemd (code=exited, status=0/SUCCESS)
Process: 6645 ExecStartPre=/opt/isec/ens/threatprevention/bin/kernelModuleControlWrapper.sh systemd (code=exited, status=0/SUCCESS)
Process: 6634 ExecStartPre=/opt/isec/ens/threatprevention/bin/AacModuleControlWrapper.sh systemd (code=exited, status=0/SUCCESS)
Main PID: 6694 (isectpd)
Memory: 345.7M
CGroup: /system.slice/isectpd.service
|-6694 /opt/isec/ens/threatprevention/bin/isectpd
|-6741 /opt/isec/ens/threatprevention/bin/isectpd
|-6779 /opt/isec/ens/threatprevention/bin/isectpd
`-6788 /opt/isec/ens/threatprevention/bin/isectpd
Dec 05 17:19:27 localhost.localdomain systemd[1]: Starting McAfee Endpoint Security for Linux Threat Prevention...
Dec 05 17:19:27 localhost.localdomain systemd[1]: Started McAfee Endpoint Security for Linux Threat Prevention.
3. OAS scanning is enabled:
/opt/isec/ens/threatprevention/bin/isecav --getoasconfig --summary
On-Access Scan: Enabled and Compliant
Profile Setting: Standard
Maximum scan time: 45
GTI: Enabled
GTI Sensitivity Level: Medium
4. We use wget command to download EICAR test file(eicar.com) to /tmp, /tmp is not excluded.
5. As per mcafee kb88812, i also checked the isecoasmgr.log, it didn't contain any detection history:
Dec 05 17:20:20 localhost.localdomain INFO OASManager [6788] Starting OAS Manager
Dec 05 17:44:25 localhost.localdomain ERROR OASManager [6788] Skipping since file path /tmp/tmp.aJdI3qPC03/isecesp-mer.txt could not be opened due to - No such file or directory
Dec 05 17:44:26 localhost.localdomain ERROR OASManager [6788] Skipping since file path /opt/isec/ens/threatprevention/bin/isecesp-mer.txt could not be opened due to - No such file or directory
Dec 05 17:44:26 localhost.localdomain ERROR OASManager [6788] Skipping since file path /opt/isec/ens/threatprevention/bin/isecesp-mer.txt could not be opened due to - No such file or directory
Can you guide me on how to further troubleshoot this issue? thanks.
Solved! Go to Solution.
It's working now. not sure why it didn't working yesterday...
Hi @Former Member ,
Good day to you!
Did you confirm if the EICAR file was downloaded on to the machine?
By default the extension ".COM" is not added to the exclusion list hence you should be definitely seeing the detection under isecoasmgr.log.
I also would suggest you to perform the standard method of performing an EICAR test. Steps as below.
1. Vim or Vi EICAR.com
2. Save the Eicar string
Yes we can confirm the eicar test file is correct retrieved to /tmp. we also gave it execution permission and try to run it, but it was still not being detected by ENSLTP..
Will let my customer try your suggestion and update you. thanks.
It's working now. not sure why it didn't working yesterday...
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA