TP149 - is Recent events working correctly?

Lord_Ami Posts: 70 Active Engager

So in VM I tend to test protection capabilities. Now, I have password protected archive with malware inside and as soon as I extract it, FS deleted 3 files right away.

Original archive contents:


It leaves 4 files as shown here:


Now, the Recent events shows only 1 file detected


After running remaining files, they are blocked and it's visible from the UI



Am I doing something wrong? Where are 2 files that were supposed to be blocked (but not shown in log)?

I have the archive ready if you need it (I won't post here as it may be prohibited to distribute malware).



This discussion has been closed.