Endpoint Protection

 View Only
  • 1.  SEPM quarantined files upload - files not pristine

    Posted 17 days ago

    Hi community,

    we have enabled the "Upload quarantined files from the clients" feature within our default SEPM domain.

    This works really well and all "detections" are uploaded to the central SEPM server, but when I try to download the samples from SEPM server for further analysis the file I get seems not to be pristine.

    Is there something that I am missing (e.g. a tool to decode/unpack the file)?

    I don't get the point of uploading files to SEPM, if I can't use them afterwards.

    best regards,

    Michael



  • 2.  RE: SEPM quarantined files upload - files not pristine

    Posted 14 days ago

    Is nobody using this feature, or is nobody facing this issue?




  • 3.  RE: SEPM quarantined files upload - files not pristine

    Broadcom Employee
    Posted 14 days ago

    They are encoded so administrators don't drop a load of malicious files onto their SEPM when they select-all and download. But you can safely upload them to symsubmit.symantec.com for analysis. Please open a case with technical support if you must know how to decode them. Thanks!




  • 4.  RE: SEPM quarantined files upload - files not pristine

    Posted 7 days ago

    Thank you! We have opened a ticket regarding this topic...

    best regrards

    Michael