Endpoint Protection

 View Only
  • 1.  SEPM quarantined files upload - files not pristine

    Posted Mar 14, 2023 05:00 AM

    Hi community,

    we have enabled the "Upload quarantined files from the clients" feature within our default SEPM domain.

    This works really well and all "detections" are uploaded to the central SEPM server, but when I try to download the samples from SEPM server for further analysis the file I get seems not to be pristine.

    Is there something that I am missing (e.g. a tool to decode/unpack the file)?

    I don't get the point of uploading files to SEPM, if I can't use them afterwards.

    best regards,

    Michael



  • 2.  RE: SEPM quarantined files upload - files not pristine

    Posted Mar 16, 2023 10:36 AM

    Is nobody using this feature, or is nobody facing this issue?




  • 3.  RE: SEPM quarantined files upload - files not pristine

    Broadcom Employee
    Posted Mar 17, 2023 03:54 AM

    They are encoded so administrators don't drop a load of malicious files onto their SEPM when they select-all and download. But you can safely upload them to symsubmit.symantec.com for analysis. Please open a case with technical support if you must know how to decode them. Thanks!




  • 4.  RE: SEPM quarantined files upload - files not pristine

    Posted Mar 23, 2023 10:33 AM

    Thank you! We have opened a ticket regarding this topic...

    best regrards

    Michael