Hello,
I got a question about the Adaptive Threat Protection end user response field when ATP alerting when a file is about to be executed.
The end-user have a text box and an option to send some test to the administrator.
Send information about this file or your decision to your administrator
How can this response text be collected by the administrator? In the ATP User Guide, nothing is explained about this.
BR
That's a good question. You're right it's not documented anywhere that I can find. I have not had time to test it yet but I would assume it would show up somewhere in Reporting/ATP Events. There isn't really anywhere else that ATP would be relevant in EPO.
This would be a very useful feature if someone could find out how to actually use it 🙂 Someone at McAfee should know how to use it... or? 😉
- Create a new query
- Select Events
- Select Adaptive Threat Protection Events
- Next
- Table
- Next
- Add User Prompt Comments
- Next
- Add User Prompt Comments
- Choose Value is not Blank
- Run/Save
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: