In the recently upgraded Forticloud portal under the Sandbox tab I can see 4 files over the past week classified as 'High Risk' (they show as 'Malicious' in the FortiSandbox console on the appliance).
When I go to view their details, on the portal they are blank, and I can find no way of actually establishing what files they were.
Each of the 4 files have an associated 'Email Sent Time' entry on the Portal. None of these emails were received (checked in Spam and mail server queues) and I can see no indication that they have ever really been sent.
The files concerned are part of expected FTP traffic overnight generated by a scheduled task to perform a backup of our live websites (msdeploy, 7zip). This task has been in place over 5 months and runs daily, however only 4 high risk alerts (2 blocks of 2 4 days apart) have been raised in the past 31 days
How do I establish which files these are (and why they are being classified as malicious) through the Sandbox?
Surely there is some way of determining which files are (occasionally) tripping the Sandbox malicious file detection.
I'd rather not have to diff the source and destination..
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
hfreel wrote:Good luck. Let me know how you make out.
Fix has been rolled out to FortiCloud and I've been advised that the 'Alert Emails' were not actually sent - part of the same issue apparently.
I'm told that this is now all resolved, and the ticket has been closed.
Hopefully you won't see the issue any more either.
OK Thanks, I'll keep an eye on it.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1660 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.