cancel
Showing results for 
Search instead for 
Did you mean: 
Omriil
Level 8
Report Inappropriate Content
Message 1 of 4

VirusScan For Storage - How to find out the file's original path on the storage server

we are using VSES with ICAP scan, and all the threat alerts are showing the local temp folder as the Threat Target File Path (both in ePO and in the local Path), which makes sense because VSES copies the file than scans it locally, but we wish to know the original path of the detected threat on the storage server. could this be done somehow? maybe if we can insert this info to the ICAP request there will be some sort of output on ePO/VSES side?

3 Replies
McAfee Employee akatt
McAfee Employee
Report Inappropriate Content
Message 2 of 4

Re: VirusScan For Storage - How to find out the file's original path on the storage server

ICAP requests are scanned locally on the VSES scan server, yes, but it isn't VSES that performs the delete.  VSES should be informing the ICAP Client about the "infected" file, for which the ICAP device then takes the appropriate action.  

I won't profess to be an expert with the ICAP Client side, but I would imagine that the ICAP Client has a method of reporting this deletion that it performs.

Based on the problem statement, it leads me to believe that the event you are seeing is actually the On-Access Scanner for VSE (not VSES), deleting something like EICAR test files as they are copied over to the scan server.  In order to avoid this, we need to add an exclusion within VirusScan Enterprises' On-Access Scanner, for the **\VSEICAPTempFiles\ folder location (and sub-folders), so that the OAS for VSE doesn't detect/delete the files as they are copied over to the ICAP server for scanning.

Here is the KB for reference:
https://kc.mcafee.com/corporate/index?page=content&id=KB81933


Also, our apologies for such a delayed reply.  I trust that if this became a business impact for the company, that a service requests was opened and fulfilled by support by now.


Was my reply helpful?

If this information was helpful in any way, or answered your question, will you please select "Accept as Solution" in my reply, or give kudos as appropriate, so together we can help other members?



Omriil
Level 8
Report Inappropriate Content
Message 3 of 4

Re: VirusScan For Storage - How to find out the file's original path on the storage server

Hi,

What you are describing is not the issue. We already have this exclusion set up in the VSE OAS Policy, and the events are definitely VSES events and the files are not EICAR or other test.

I'm talking about real threats found by VSES, it's just that in the event the "Threat Target File Path" is showing the local TEMP folder on the server which VSES is installed on, and what we want to know is the original location of the file on the NAS system- either a share name or a disk volume location. Right now we are seeing malicious files that are found on the storage system, but we have no idea from which folders they came from and where can we find these files.

McAfee Employee akatt
McAfee Employee
Report Inappropriate Content
Message 4 of 4

Re: VirusScan For Storage - How to find out the file's original path on the storage server

The product has the ability to report the "Threat Source Hostname," but I never recalled seeing the actual file path on the ICAP Client, simply because the ICAP request just performs a "get" on the file.

ICAP scanning isn't as granular as NetApp scanning, where the VSES scanner actually reaches out and gets a handle on the file request, directly on the filer, and as such has the ability to report the full file path.

What would be helpful, is to have an enhancement request logged, so that hopefully the feature can be implemented at some point.  This may not be possible simply based on how the product currently functions, but ultimately that call resides with Product Management and Engineering, who does review the submitted ideas.

https://kc.mcafee.com/corporate/index?page=content&id=KB60021

More McAfee Tools to Help You
  • Subscription Service Notification (SNS)
  • How-to: Endpoint Removal Tool
  • Support: Endpoint Security
  • eSupport: Policy Orchestrator
  • Community Help Hub

      New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

    • Find Forum FAQs
    • Learn How to Earn Badges
    • Ask for Help
    Go to Community Help

    Join the Community

      Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

    • Get helpful solutions from McAfee experts.
    • Stay connected to product conversations that matter to you.
    • Participate in product groups led by McAfee employees.
    Join the Community
    Join the Community