Collecting Malware InfoΒΆ

When running, the Agent collects information about executable files on the endpoint, including but not limited to their source, file have, and signatures. The information collected may be provided to a vendor or third party for analysis.The information collected is not provided for any purpose other than malicious code detection and analysis.

  • Detection results are provided in real time.
  • Results may differ from similar solutions. User/ Administrator is responsible for actions taken in response to the results.
  1. Go to Policy in the top panel.
  2. Go to Policy > Node Policy > Agent Action in the left Policy panel.
  3. Find and click Collect Malware Information in the Agent Action window.
  4. Enter in CWP message, Conditions, based off of your network requirements.

Under Consent Agreement section:

  1. Select I Agree from the drop down to consent to sharing endpoint data for threat analysis.

Under Collection Exceptions section:

  1. List directories to exempt from data collection. Commonly exempted sections include antivirus quarantine folders, or other directories where known malicious files may be stored.
  2. Click Update.

To Apply this Agent Action to a Node Policy:

  1. Go to Node Policy in the left Policy panel.
  2. Click the [Desired Node Policy] in Node Policy window.
  3. Find Agent Action. Click Assign.
  4. Find Collect Malware Information in the Available section. Select and drag it into the Selected section.
  5. Click Add.
  6. Click Update.