Hi, what is the criteria when an app gets "released from containment"?
Why would an app get contained then only to be released and at the request of ATP? Does the process get re-scanned/evaluated when it is accessed again and the reputation changed on the 2nd scan/evaluation?
Description:
The application <some.exe> was released from containment at the request of Adaptive Threat Protection. |
Event Category:Event ID:Threat Severity:Threat Name:Threat Type:Action Taken:Threat Handled:Analyzer Detection Method:
'Process' class or access |
37276 |
Warning |
DAC:Released |
Dynamic Application Containment |
Released from containment |
True |
Dynamic Application Containment |
Hello @JKBH1 ,
Thank you for reaching out McAfee Enterprise Support Community.
Adaptive Threat Protection uses an application's reputation to determine whether Dynamic Application Containment runs the application with restrictions. Dynamic Application Containment blocks or logs unsafe actions of the application, based on containment rules.
As applications trigger containment block rules, Dynamic Application Containment uses this information to contribute to the overall reputation of contained applications.
Other technologies, such as McAfee® Active Response, can request containment. If multiple technologies registered with Dynamic Application Containment request to contain an application, each request is cumulative. The application remains contained until all technologies release it. If a technology that has requested containment is disabled or removed, Dynamic Application Containment releases those applications.
Please do check with the work flow in the below mentioned article,
Was my reply helpful?
If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
The reputation changes from a TIE server or the app terminates. The reputation will be cached until one of the following 1) JCM cache is cleared 2) TIE server pushes down a new reputation 3) added to Trust dats. If a lookup fails, it will scan again at the next execution, but only if the first instance of the app terminates.
Dave
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: