yakubi Posted 01 Aug 2023 10:13

Engine Zero and Endpoint Secure Detection Analysis

I am currently conducting a test with a potentially malicious application on my desktop with Endpoint Secure. During the test, ES successfully detected the application as malicious. However, when I uploaded the same application to VirusTotal for analysis, the Sangfor Engine Zero did not identify it as a threat, as shown in the screenshot below.

ES Detection Log
Virustotal Analysis Result.

CLELUQMAN Posted 01 Aug 2023 10:36

Thank you for sharing your findings.

Faixan Posted 01 Aug 2023 14:54

good information:victory:

Jami Ullah Posted 01 Aug 2023 17:05

Thanks for sharing the specific use case of ES.

Newbie517762 Posted 01 Aug 2023 17:26

If you require any assistance, please do not hesitate to contact the Sangfor support team for my suggestion.

rivsy Posted 02 Aug 2023 15:15

thank you for the information

Siva Posted 02 Aug 2023 20:12

Dear Yakubi,

The reason for that is the Endpoint Secure uses different engines to determine a file is malicious.The fact that you are able to scan the file as threat from Endpoint Secure shows that the file has been detected as a threat by one of the engine. (Definitely not Engine Zero, because as you can see from the Virus Total results it shows not detected by Engine Zero).
page: [1]
查看完整版本: Engine Zero and Endpoint Secure Detection Analysis