cancel
Showing results for 
Search instead for 
Did you mean: 
McDuff
Level 10
Report Inappropriate Content
Message 1 of 3

Templates for Automated Response Emails for Malware Events

Jump to solution

Greetings

Wondering if anyone has suggestions for Automated Response emails for notifying security staff of ENS malware events.  Our security team and service desk wants informational email sent when malware events occur which clearly and simply state the who, what, when, where, etc without having to log into ePO.

One tidbit of information that people find useful is Endpoint Security Description under Threat Events for the system within ePO (see screenshot).

I've been playing with the variables in the Automated Response email template, and I so far haven't been able to find the correct variables to recreate what's written the Description field.

Wondering if any of you can send ideas for useful automated response emails.

AR.png

1 Solution

Accepted Solutions
ChrisQ
Level 9
Report Inappropriate Content
Message 2 of 3

Re: Templates for Automated Response Emails for Malware Events

Jump to solution

To get that line, use something like:

{targetUserName} ran {sourceProcessName} which tried to access {targetFileName}. The {threatType} named {threatName} was the {eventDesc}

It won't be exactly the same but it will be close

For when, use {detectedUTC}

I also use Threat handled?: {threatHandled}   which gives True or False

2 Replies
ChrisQ
Level 9
Report Inappropriate Content
Message 2 of 3

Re: Templates for Automated Response Emails for Malware Events

Jump to solution

To get that line, use something like:

{targetUserName} ran {sourceProcessName} which tried to access {targetFileName}. The {threatType} named {threatName} was the {eventDesc}

It won't be exactly the same but it will be close

For when, use {detectedUTC}

I also use Threat handled?: {threatHandled}   which gives True or False

Highlighted
McDuff
Level 10
Report Inappropriate Content
Message 3 of 3

Re: Templates for Automated Response Emails for Malware Events

Jump to solution

Many thanks!

More McAfee Tools to Help You

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community