TP149 - is Recent events working correctly?
So in VM I tend to test protection capabilities. Now, I have password protected archive with malware inside and as soon as I extract it, FS deleted 3 files right away.
Original archive contents: http://snag.gy/EsL6U.jpg
It leaves 4 files as shown here:
Now, the Recent events shows only 1 file detected
After running remaining files, they are blocked and it's visible from the UI
Am I doing something wrong? Where are 2 files that were supposed to be blocked (but not shown in log)?
I have the archive ready if you need it (I won't post here as it may be prohibited to distribute malware).
Comments
-
Hello,
Sorry for my reply.
Maybe if I normally understand your situation.... it's can be related with my next "experience about explanation... why it's work like that" and maybe situation not as design (?!).
About part of "Many detections per moment."
Sorry again.
Thanks.
🚩 What Do You Think?
We’d love your thoughts on our fresh look! Quick survey, big impact!