Follow these steps:
- Log in to Apex Central
- Navigate to Policies > Policy Management.
- Create a new policy.
- Disable Real-time Scan and Web Reputation Services.
- Ensure that Vulnerability Protection is enabled.
- Ensure that Restrict Download Of EICAR Test File Over HTTP is enabled.
- Select a demo machine and deploy the policy.
- Once done, download the Eicar test file from the link, http://files.trendmicro.com/products/eicar-file/eicar.com.
- Wait for a few minutes and verify if the detection is logged in Apex Central Log Query.
- Go to a test machine and create a shared folder with permission for everyone.
- Login to Apex Central as a Service.
- Select the policy associated to the selected machine in step 1.
- Select Vulnerability Protection Settings.
- Search for 1009490.
- Change status to Enabled.
- Click on Deploy.
- Using another machine, access the shared folder generated in the machine in step 1.
- Login to the Apex Central console and verify if the logs show up under the Intrusion Prevention Log Query.