Best practice: Configure an Automatic Response for malware detection

Prev Next

If malware is found by the on-demand scan in the test group, you want to block the files from being copied automatically to the Current repository. Set up an automatic notification to the administrator.

You must have already created an on-demand scan task to scan for any problems that might occur in your test group.

For details about product features, usage, and best practices, click ? or Help.

  1. To display the Response Builder, select MenuAutomationAutomatic Responses, click New Response, then configure these settings in the Descriptions tab, then click Next.

    1. Type a name, for example Malware found in test group, and a detailed description

    2. For Language, select a language from the list.

    3. For Event Group, select ePO Notification Events from the list.

    4. From Event type, select Threat from the list.

    5. For Status, select Enabled.

  2. Configure these settings in the Filter tab, then click Next.

    1. For Available Properties list, select Threat Category.

      Optionally, you can add additional categories, such as an access protection rule being triggered.

    2. In the Required Criteria column and the Defined at row, click ... to select the test group of systems that you created in the Select System Tree Group dialog box, then click OK.

    3. In the Threat Category row, select Belongs to from the Comparison list and Malware from the Value list. Click + to add another category.

    4. Select Belongs to from the Comparison list and Access Protection from the Value list.

  3. Configure these settings in the Aggregation tab, then click Next.

    1. For Aggregation, click Trigger this response for every event.

    2. Do not configure any Grouping or Throttling settings.

  4. Configure these settings in the Actions tab:

    1. Select Send Email from the Actions list.

    2. For Recipients, type the email address of the administrator to be notified.

    3. For Importance, select High from the list.

    4. For Subject, type an email header, for example Malware found in the Test Group!

    5. For Body, type a message, for example Research this NOW and stop the server task that pulls content into the Current branch!

    6. Following the message body, insert these variables to add to the message, and click Insert:

      • OS Platform

      • Threat Action Taken

      • Threat Severity

      • Threat Type

  5. Click Next, confirm that the configuration is correct in the Summary tab, then click Save.

Now you have an Automatic Response configured that sends an email to an administrator any time malware is detected in the test group running the Evaluation DAT file.