Sign In with your
Trend Micro Account
需要協助?
需要協助?

若您需要技術支援,請 按此建立案件。

How to isolate an OfficeScan endpoint via the Control Manager (TMCM) 7.0 web console

    • 更新於:
    • 24 Feb 2020
    • 產品/版本:
    • Control Manager 7.0
    • OfficeScan XG
    • 作業系統:
概要

The steps provided in this article are based on an actual replication of isolating an OfficeScan agent with virus detections.

詳情
Public

Enable firewall settings in the OfficeScan agent:

  1. Log on to the OfficeScan web console > Administration > Settings > Product License and check the settings.

    Isolate OSCE endpoint from TMCM

  2. Make sure that the OfficeScan agent was able to apply the settings.

    Isolate OSCE endpoint from TMCM

    Isolate OSCE endpoint from TMCM

  1. Log on to the OfficeScan agent and create an eicar test file using Notepad:

    Eicar String: X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*

    In the screenshot below, the test file was dropped two (2) times with filename eicartest.txt and malwaretest.txt.

    Isolate OSCE endpoint from TMCM

  2. Verify the logs in the agent console by clicking the virus/malware in the notification window on the agent side.
     
    Wait until the virus logs are sent to the OfficeScan server.
  3. Log on to the OfficeScan server and go to Logs > Agents > Security Risk.

    Security Risk Logs will open.

  4. Verify the logs in the Virus/Malware column.

    Isolate OSCE endpoint from TMCM

  5. Log on to the TMCM console and go to Directories > Users/Endpoints > Endpoint.
  6. In the Search box, select "Endpoint" then type the IP address of the target endpoint to isolate.

    In the screenshot below, the target IP address is 10.205.202.54.

     
    The OfficeScan XG server must be registered to the TMCM server.

    Isolate OSCE endpoint from TMCM

  7. Click the endpoint name in the console from Step 5.

    In this example, you have to click WIN10EECM and you will be redirected to the below page.

    Isolate OSCE endpoint from TMCM

  8. Open the Task dropdown in the uppermost part of the page and click ISOLATE.

    Isolate OSCE endpoint from TMCM

    The notification "Isolation command has been sent. Waiting for the agent to be notified" will appear.

    Isolate OSCE endpoint from TMCM

    The OfficeScan agent will receive a notification similar to below screenshots:

    Notification:

    Isolate OSCE endpoint from TMCM

    Agent console status:

    Isolate OSCE endpoint from TMCM

  9. Click OK on the Endpoint Isolated window.

    Isolate OSCE endpoint from TMCM

    The OfficeScan agent should now be isolated and ready for investigation. The isolated endpoint will still be shown as Online in the OfficeScan Agent Management console.

    Isolate OSCE endpoint from TMCM

  1. Log on to the console, then go to Directories > Users/Endpoints > Endpoint > Filters > Network Connection > Isolated.

    Isolate OSCE endpoint from TMCM

  2. Click the endpoint name from the result of step 1, then go to Task.

    It will show three (3) options:

    • Assign Tags
    • Restore
    • Modify Allowed Traffic

    Isolate OSCE endpoint from TMCM

  3. Go to Administration > Command Tracking and search for "Deploy Isolate/Restore".

    Isolate OSCE endpoint from TMCM

Premium
Internal
Partner
評價:
分類:
Configure; Remove a Malware / Virus
解決方案ID:
000243462
評定這個解決方案
本文是否幫助解決您的問題?

感謝您的意見!

請留下您的Email方便進一步的聯繫,協助我們改進文章內容:
我們不會透過以上Email寄送任何可能騷擾您的垃圾信.

本意見調查系統為自動運作,將不會回覆如銷售、技術、產品等一般問題.

若您需要協助,請聯繫對應的技術支援窗口. 聯絡我們


To help us improve the quality of this article, please leave your email here so we can clarify further your feedback, if neccessary:
We will not send you spam or share your email address.

*This form is automated system. General questions, technical, sales, and product-related issues submitted through this form will not be answered.