I have a file here which is shown as malicious in the tie.
if i scan it on my pc with a right click, this file will not be shown as a threat.
why not?
I can also continue to open the file.
For info: it is an excel file.
GTI is available
TIE server is available
Solved! Go to Solution.
Hi @cheetah,
Thank you for keeping me updated. May I know if you have any further queries as well? Feel free to ask here 🙂 Glad to be of assistance!
Hi @cheetah,
Thank you for your Post. This may take a lot of concepts involved to understand what may be going on here. Also we do not have logs files to look into and hence with the limited available information, here we go:
First: if i scan it on my pc with a right click, this file will not be shown as a threat.
why not?
Assuming you are using McAfee Endpoint Security with ATP, this is as per behavior. When TIE has determined a file to be malicious, the information can only be collected by ATP. ATP does not act upon a file for On Demand Scan. It only acts upon a file when the file is executed!
Next: I can also continue to open the file.
For info: it is an excel file.
Once again, if you are using ENS +ATP, this is again an expected behavior. An Excel file is not an application but it is a data file that cannot be scanned by ATP since it does not get executed. Interestingly this may happen with an executable as well depending on the situation and the reputation information available in your TIE Server. before we deep dive into that, I would like to ensure which product is being used here. may I know if you are using ENS and ATP here for the reported scenario?
Hi @cheetah,
Thank you for keeping me updated. May I know if you have any further queries as well? Feel free to ask here 🙂 Glad to be of assistance!
Hi @cheetah,
Excellent! I am very glad I could be of assistance. Have a nice day ahead 🙂
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA