07-25-2019 12:32 PM
Just wanting to know if someone can answer whether or not there is a way to automatically kick off a scan of any storage device when initially plugged in? We are being required by audit to automatically perform a threat/virus scan whenever a removable device (majority will be USB flash drives) are plugged into a computer. Thanks for any response.
07-29-2019 11:28 AM - edited 07-29-2019 11:32 AM
Hello @Joshua Heath,
we do not do an automated USB drive OnDemand Scan. This can also be very time and resource intensive, e.g. if you are using a Removeable Storage Device connected using USB 2.0. I know, audit guideline are important, but you may think about the following topics.
There are some interesting things about Signature based detection mechanism we should think about.
What we are doing, or, what we are doing more than traditional AV (some info, I´m not aware how familiar you are with AMP).
For Threat Hunting we need the behaviour information for known good files.
Below you can see the monitored activity (process, file, network and command line) from a good file.
Hope this helps,
Greetings, Thorsten
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide