How often does that happen?

It’s a so called false positive or why would you want to get it back?

 

My point being, yes it’s free, it’s pretty quiet, easy to manage and
sometimes you may have to do something manually.

If you want more, pay for it (more) and manage it more?

 

 

From: [email protected] [mailto:[email protected]]
On Behalf Of Marcum, John
Sent: Mittwoch, 3. Juni 2015 22:07
To: [email protected]
Subject: RE: [mssms] SCEP poll

 

Files that were quarantined. I needed to have them pulled from backups. 

 

From: [email protected] <mailto:[email protected]>
[mailto:[email protected]] On Behalf Of Kent, Mark
Sent: Wednesday, June 3, 2015 3:05 PM
To: [email protected] <mailto:[email protected]> 
Subject: RE: [mssms] SCEP poll

 

What files did you need to have restored?

Sent from my Windows Phone

  _____  

From: Marcum, John <mailto:[email protected]> 
Sent: ‎6/‎3/‎2015 3:33 PM
To: [email protected] <mailto:[email protected]> 
Subject: RE: [mssms] SCEP poll

I would have but every time I do Mott pokes me with a stick. :)

 

 

This was the MAIN reason I decided to get rid of it however I “think” they
have improved on this some. “, is a decentralized storage of quarantined
files… if I need to dynamically analyze malware to create IOCs for it, then
I am stuck chasing the end-client” There’s also not any good centralized
reporting on cleaned/quarantined files out of the box BTW.

 

Essentially you are getting what you pay for. If you are just trying to CYA
by checking a box on an audit form that says “Do you have anti-virus
installed” you are fine. Most viruses that are bad are zero day attacks that
no product is going to catch anyway. I just don’t want to be the AV dude
when one of those does hit. I don’t want to be the guy that says, “Sorry we
can’t get your files back without visiting every desktop” which is what CSS
told me I’d need to do. (again, I think it’s better now but I have no proof
of that)

 

….And there’s my rant Mott, feel free to call me names!

 

 

From: [email protected] <mailto:[email protected]>
[mailto:[email protected]] On Behalf Of Gilmanov, Nile
Sent: Wednesday, June 3, 2015 2:06 PM
To: [email protected] <mailto:[email protected]> 
Subject: RE: [mssms] SCEP poll

 

I am surprised nobody mentioned that SCEP ahem lacks very much compared to
other real-world products.

 

http://chart.av-comparatives.org/awards_by_vendor.php?venID=11 It mostly
doesn’t make any security lists and last awards MS got was in 2012.

 

Does it generally detect and clean stuff up yeah I agree it that it does. My
personal beef with it, is a decentralized storage of quarantined files… if I
need to dynamically analyze malware to create IOCs for it, then I am stuck
chasing the end-client. Even then there are no good tools to unpack the
samples, other than letting your own app do that… thus you must be running
SCEP to unpack the stuff. Pretty counter-intuitive compared to Trend.

 

 

Nile Gilmanov

Systems Administrator

Wabash National Corporation

 <mailto:[email protected]> [email protected]
| O: 765.772.2691 | M: 765.414.7402 | F: 765.449.5381

 

From: [email protected] <mailto:[email protected]>
[mailto:[email protected]] On Behalf Of Ed Aldrich
Sent: Wednesday, June 3, 2015 2:12 PM
To: [email protected] <mailto:[email protected]> 
Subject: RE: [mssms] SCEP poll

 

:)

 

 

From: [email protected] <mailto:[email protected]>
[mailto:[email protected]] On Behalf Of Heaton, Joseph@Wildlife
Sent: Wednesday, June 03, 2015 1:23 PM
To: '[email protected]'
Subject: RE: [mssms] SCEP poll

 

You sound offended, yet you knew he was talking about you?  :)

 

From: [email protected] <mailto:[email protected]>
[mailto:[email protected]] On Behalf Of Marcum, John
Sent: Wednesday, June 03, 2015 10:15 AM
To: [email protected] <mailto:[email protected]> 
Subject: RE: [mssms] SCEP poll

 

“The Detractor”… Is that my new name? Just because I don’t LOVE all things
MS???

 

From: [email protected] <mailto:[email protected]>
[mailto:[email protected]] On Behalf Of Michael Mott
Sent: Wednesday, June 3, 2015 11:16 AM
To: [email protected] <mailto:[email protected]> 
Subject: RE: [mssms] SCEP poll

 

I only saw one email from the detractor!  Amazing!

 

From: [email protected] <mailto:[email protected]>
[mailto:[email protected]] On Behalf Of Roland Janus
Sent: Wednesday, June 03, 2015 5:11 AM
To: [email protected] <mailto:[email protected]> 
Subject: [mssms] SCEP poll

 

That likely has been asked before.

 

How many of you, using CM, also use SCEP on clients?

 

I’m not looking for reasons, a simple yes/no will do.

Maybe you can throw in some client numbers?

 

I’ll start:

 

Not decided yet  :), 1000 clients

 

Thanks, Roland

 

 

 

  _____  



Legal Notice: This email is intended only for the person(s) to whom it is
addressed. If you are not an intended recipient and have received this
message in error, please notify the sender immediately by replying to this
email or calling +44(0) 2083269015 (UK) or +1 866 592 4214 (USA). This email
and any attachments may be privileged and/or confidential. The unauthorized
use, disclosure, copying or printing of any information it contains is
strictly prohibited. The opinions expressed in this email are those of the
author and do not necessarily represent the views of 1E Ltd. Nothing in this
email will operate to bind 1E to any order or other contract.

  _____  


Confidentiality Notice: This e-mail is from a law firm and may be protected
by the attorney-client or work product privileges. If you have received this
message in error, please notify the sender by replying to this e-mail and
then delete it from your computer.

 

 

 

  _____  



Legal Notice: This email is intended only for the person(s) to whom it is
addressed. If you are not an intended recipient and have received this
message in error, please notify the sender immediately by replying to this
email or calling +44(0) 2083269015 (UK) or +1 866 592 4214 (USA). This email
and any attachments may be privileged and/or confidential. The unauthorized
use, disclosure, copying or printing of any information it contains is
strictly prohibited. The opinions expressed in this email are those of the
author and do not necessarily represent the views of 1E Ltd. Nothing in this
email will operate to bind 1E to any order or other contract.

 

 

 

 

 




Reply via email to