Sign In with your
Trend Micro Account
Need Help?
Need More Help?

Create a technical support case if you need further support.

How to isolate an OfficeScan endpoint via the Control Manager (TMCM) 7.0 web console

    • Updated:
    • 24 Feb 2020
    • Product/Version:
    • Control Manager 7.0
    • OfficeScan XG
    • Platform:
Summary

The steps provided in this article are based on an actual replication of isolating an OfficeScan agent with virus detections.

Details
Public

Enable firewall settings in the OfficeScan agent:

  1. Log on to the OfficeScan web console > Administration > Settings > Product License and check the settings.

    Isolate OSCE endpoint from TMCM

  2. Make sure that the OfficeScan agent was able to apply the settings.

    Isolate OSCE endpoint from TMCM

    Isolate OSCE endpoint from TMCM

  1. Log on to the OfficeScan agent and create an eicar test file using Notepad:

    Eicar String: X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

    In the screenshot below, the test file was dropped two (2) times with filename eicartest.txt and malwaretest.txt.

    Isolate OSCE endpoint from TMCM

  2. Verify the logs in the agent console by clicking the virus/malware in the notification window on the agent side.
     
    Wait until the virus logs are sent to the OfficeScan server.
  3. Log on to the OfficeScan server and go to Logs > Agents > Security Risk.

    Security Risk Logs will open.

  4. Verify the logs in the Virus/Malware column.

    Isolate OSCE endpoint from TMCM

  5. Log on to the TMCM console and go to Directories > Users/Endpoints > Endpoint.
  6. In the Search box, select "Endpoint" then type the IP address of the target endpoint to isolate.

    In the screenshot below, the target IP address is 10.205.202.54.

     
    The OfficeScan XG server must be registered to the TMCM server.

    Isolate OSCE endpoint from TMCM

  7. Click the endpoint name in the console from Step 5.

    In this example, you have to click WIN10EECM and you will be redirected to the below page.

    Isolate OSCE endpoint from TMCM

  8. Open the Task dropdown in the uppermost part of the page and click ISOLATE.

    Isolate OSCE endpoint from TMCM

    The notification "Isolation command has been sent. Waiting for the agent to be notified" will appear.

    Isolate OSCE endpoint from TMCM

    The OfficeScan agent will receive a notification similar to below screenshots:

    Notification:

    Isolate OSCE endpoint from TMCM

    Agent console status:

    Isolate OSCE endpoint from TMCM

  9. Click OK on the Endpoint Isolated window.

    Isolate OSCE endpoint from TMCM

    The OfficeScan agent should now be isolated and ready for investigation. The isolated endpoint will still be shown as Online in the OfficeScan Agent Management console.

    Isolate OSCE endpoint from TMCM

  1. Log on to the console, then go to Directories > Users/Endpoints > Endpoint > Filters > Network Connection > Isolated.

    Isolate OSCE endpoint from TMCM

  2. Click the endpoint name from the result of step 1, then go to Task.

    It will show three (3) options:

    • Assign Tags
    • Restore
    • Modify Allowed Traffic

    Isolate OSCE endpoint from TMCM

  3. Go to Administration > Command Tracking and search for "Deploy Isolate/Restore".

    Isolate OSCE endpoint from TMCM

Premium
Internal
Partner
Rating:
Category:
Configure; Remove a Malware / Virus
Solution Id:
000243462
Feedback
Did this article help you?

Thank you for your feedback!

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.

If you need additional help, you may try to contact the support team. Contact Support

To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.