We are looking at specific threat events, and I was hoping to get more clarity on how the Threat Source / Target fields are populated. This is for a network where Host A is ePO connected, and Host B is not ePO connected.
Host A reported an event, showing Host B as Threat Source, and Host A as Threat Target.
A few specific questions arise:
1. Must Host B be running a McAfee AV product for Host A to flag the event?
2. What mechanism does McAfee use when assigning values to these fields, i.e. what criteria does McAfee use to determine what the Threat Source is?
3. What would the best way be to interpret a situation where the Threat Source is different from the Threat Target? e.g. Is Host B trying to spam malware across the network? Are detection events just forwarded to Host A and flagged in ePO as such, since Host B is not connected to ePO?
4. Which log file would give the most details about these threat events?
Would appreciate any information / detail that would clarify any of the above points, thanks!
Solved! Go to Solution.
My apologies, but these are really all questions that need to be answered in the group associated to the point product that is running the scanner - presumably either ENS or VSE ?
ePO only records the events, it does not create them.
Events are created by the locally installed scanner, then passed through the McAfee Agent to the ePO server.
If you can post to whichever point-product group is relevant to your installation, they should be better placed to help answer your questions.
Thx.
My apologies, but these are really all questions that need to be answered in the group associated to the point product that is running the scanner - presumably either ENS or VSE ?
ePO only records the events, it does not create them.
Events are created by the locally installed scanner, then passed through the McAfee Agent to the ePO server.
If you can post to whichever point-product group is relevant to your installation, they should be better placed to help answer your questions.
Thx.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA