Enterprise Console: managing console alerts after install or upgrade
When you first install Enterprise Console version 3 or above you may well see alerts in the console. These could be virus alerts, or they could be alerts for Potentially Unwanted Applications (PUAs) or suspicious files. These alerts are generated as workstations run files identified as potential threats.
- A fresh Enterprise Console installation will alert on files showing suspicious behavior, but will not block them (alert only mode).
- An upgraded Enterprise Console will neither alert on, nor block, files showing suspicious behavior.
- If you upgraded from Enterprise Console version 1 in the past, scanning for PUAs and adware may not be enabled (it will be otherwise).
Note: PUA and suspicious behavior alerts will only be generated by computers running Sophos Anti-Virus for Windows 2000+.
What to do
Deal with any existing threats before enabling new features.
1. Dealing with existing threats
You should deal with any alerts for viruses, Trojans, worms or spyware first. See Enterprise Console: removing viruses for details.
If you did not enable scanning for PUAs and adware when upgrading from Enterprise Console version 1, see the PUA rollout guide.
2. Enabling alert only mode on upgraded networks
Programs showing suspicious behavior will be detected (but not currently blocked) by fresh installations of Enterprise Console.
If you have upgraded, you should now enable alert only mode.
- If necessary, open Enterprise Console.
- In the Enterprise Console Policies pane, double-click 'Anti-virus and HIPS'.
- Double-click your policy.
- Click 'HIPS runtime behavior'.
- Select the following check boxes:
- Detect suspicious behavior
- Detect buffer overflows
- Alert only
- Click 'OK' to close the dialog boxes and save your changes.
3. Monitoring programs showing suspicious behavior
Leave your computers running in alert only mode for at least a week.
- If you get a huge number of alerts, identify which programs are generating the majority of them and deal with those programs immediately. Then continue monitoring.
- Once you have a good understanding of which programs are involved, you can authorize those that you need.
- You should then monitor alerts for a further period to check that enabling blocking will not disrupt your network.
You can enable blocking once you are satisfied that this will cause no disruption.
For more details, see Sophos Anti-Virus for Windows 2000+: deciding whether to allow or block a file.
4. Enabling on-access scanning for suspicious files
On-access scanning will block the running of suspicious files and send a report to the console. Only enable it once you are confident that useful software will not be blocked, and that the console will not be sent vast numbers of alerts.
- If necessary, open Enterprise Console.
- In the Enterprise Console Policies pane, double-click 'Anti-virus and HIPS'.
- Double-click your policy.
- If on-access scanning for viruses is not already selected, select 'Enable on-access scanning'.
- Click 'On-access scanning'.
- In the 'On-access scan settings' dialog box, select 'Scan for suspicious files (HIPS)'.
- Click 'OK' in each dialog box to save your scan.
You can deal with the files reported using 'Cleanup', or a scheduled scan.
5. Setting automatic cleanup for scheduled scans
You can keep your network free of suspicious files by setting up scheduled scans to detect and remove files.
Note:
- This could disrupt the operation of recently installed software. Only enable automatic cleanup if you are confident that no useful software will be deleted.
- Alternatively, run a scheduled scan, but use Cleanup to deal with alerts in the console.
To set up a scheduled scan, do as follows.
- If necessary, open Enterprise Console.
- In the Enterprise Console Policies pane, double-click 'Anti-virus and HIPS'.
- Double-click your policy.
- In the 'Scheduled scanning' section, click 'Add'.
- Give the scan a name, and select a time for it to run.
If you want to enable automatic removal, also do the following:- Click 'Configure'.
- In the 'Scanning and cleanup settings' dialog box for your new scan, select the 'Cleanup' tab.
- In the 'Suspicious files' section, select 'Delete' or one of the 'Move...' options.
- Click 'OK' in each dialog box to save your scan.
Related articles:
- Sophos Anti-Virus for Windows 2000+: application control rollout guidelines
- Sophos Endpoint Security: administrator's rollout guide for potentially unwanted application (PUA) protection
- Sophos Client Firewall: Administrator roll-out guidelines
If you need more information or guidance, then please contact technical support.
- Article ID: 25329
- Created: 16 May 2007
- Last updated: 13 Oct 2008
