Hi All,
Is their a way to isolate devices in mcafee from the companies network to investigate incidents/threats ??
It all depends on the products you have installed. You can push firewall rules to block network access, but once you do that, you will only have local access to the system. What products do you have installed?
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
I have ATP, TP, WC, and firewall
I am going to move this thread to the ens team - they can assist better with defining any type of rules to accomplish this.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Hi @Waseem_a
There are several recommendations written in ENS Product Guide; There are several Access Protection rules that designed to be activated during malware outbreaks;
Endpoint Security 10.6.x Threat Prevention Product Guide (ePO managed)
Product Documentation ID: PD27574
This is a HIPS article but you can can same rules in ENS Exploit prevention:
Best Practices for how to use Host IPS rules for a malware outbreak
Technical Articles ID: KB84507
Additionally this KB article can help as you have ATP
List of and best practices for Endpoint Security Dynamic Application Containment rules
Technical Articles ID: KB87843
New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.
Thousands of customers use our Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership: