Endpoint Protection

 View Only
  • 1.  What's the process submit

    Posted Oct 05, 2012 11:12 PM


    I wan to know what's the process for Submit Suspicious Files.

  • 2.  RE: What's the process submit

    Broadcom Employee
    Posted Oct 05, 2012 11:17 PM

    Submit Portal : https://submit.symantec.com/websubmit/essential.cgi


    based on support entitlement



    Q) How do I submit suspicious files to Symantec?

    A) - Basic customers can submit up to 9 files in a compressed file at once via  Symantec's Web Submission Site. These

    MUST be in either a WinRAR or WinZIP format.

    Essential and Business Critical customers should call Support for access to our priority queues.


    Q) Is this a secure submission site?

    A) Yes. This site uses HTTPS. It also takes advantage of Secure Socket Layer (SSL) and 128-bit encryption, providing a

    secure method of transporting the files to Symantec. If you have not previously used the web submission site, please contact support for the URL.


    Q) What information is needed to submit through the web submission site?

    A) You will need to provide your name, company name, email address and Support ID number.


    Please note: In the past, you may have used your Contact ID number to submit files to Security Response. The use of the Contact ID number for submissions is being discontinued in favor of the Support ID number in order to simplify submissions. Please use your Support ID number going forward.


    Q) Where can I find my Support ID number?


    A) Your Support ID number is written on your Symantec support certificate. Your Support ID number is a twelve digit number in the following format: XXXX-XXXX-XXXX. More information regarding your Support ID number can be found here.


    Q) How many files may I submit?

    A) You may upload multiple files at once by using WinZip or WinRar. A zipped file must not be password-protected.

    The maximum size for one submission is 10 MB. Please submit no more than 9 files in any zip file regardless of size. Its important to note that some file types, like .jar and .cab may be containers and may contain files that will exceed the maximum file count.


    Q) May I provide information or ask questions at this site?

    A) The web submission form includes a field to detail symptoms you believe are associated with this file. Security

    Response engineers do not provide answers to questions posed in this form. If you need further information, please contact support.


    Q) What happens next?

    A) The submission process follows the steps below:


    ·       You will receive an automated email reply that contains the Tracking number for this submission. Please retain this number. The sender's address will be SecurityResponse@Symantec.com. Note: if you have a TAM (Technical Account Manager) or a RPS (Remote Product Specialist), he or she will receive a copy of all automated email messages sent to you.

    ·       Your submission will be immediately scanned by our automated system using current certified and current rapid release definitions. If this file has been previously submitted, you will receive an automated closing email. The email will include the known determination and, if malicious or a security risk, instructions on how to retrieve definitions that will detect the file.

    ·       The Security Response engineer who reviews the file will make a determination on the status of the file. If clean, he or she will close the submission process and an automated email message will be sent identifying the file as clean.

    ·       If it is determined the file is malicious or a security risk, the engineer will create a signature that will trigger a detection on this file. He or she will then pass the submission on to a QA engineer.

    ·       Once the QA engineer has verified that the signature correctly identifies the file, that engineer will close the submission process and an automated email message will be sent. This message will indicate the determination on the file and include instructions on how to download definitions that contain the detection.


    Q) What if I want to submit a file that I believe is being falsely detected?

    A) Please submit the file via the Symantec's False Positive Submission Site. Then contact Symantec support and reference the tracking number found in the automated email reply.

  • 3.  RE: What's the process submit
    Best Answer

    Broadcom Employee
    Posted Oct 05, 2012 11:18 PM

    also check this article

    Using Symantec Support Tool, how do we Collect the Suspicious Files and Submit the same to Symantec Security Response Team. 

  • 4.  RE: What's the process submit

    Posted Oct 05, 2012 11:20 PM


    I agree above comments

    I would request you to submit these files to the Symantec Security Team on 




    Note: ThreatExpert is owned by Symantec.

    Also, check these Article below:

    Using Symantec Support Tool, how do we Collect the Suspicious Files and Submit the same to Symantec Security Response Team.