Engine Zero and Endpoint Secure Detection Analysis

yakubi Lv3Posted 01 Aug 2023 10:13

I am currently conducting a test with a potentially malicious application on my desktop with Endpoint Secure. During the test, ES successfully detected the application as malicious. However, when I uploaded the same application to VirusTotal for analysis, the Sangfor Engine Zero did not identify it as a threat, as shown in the screenshot below.

5164164c869bbab7d3.png
ES Detection Log

6901364c869fcef6bd.png
Virustotal Analysis Result.

Siva has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

Dear Yakubi,

The reason for that is the Endpoint Secure uses different engines to determine a file is malicious.
The fact that you are able to scan the file as threat from Endpoint Secure shows that the file has been detected as a threat by one of the engine. (Definitely not Engine Zero, because as you can see from the Virus Total results it shows not detected by Engine Zero).

7302064ca4708c7370.png
Is this answer helpful?
CLELUQMAN Lv3Posted 01 Aug 2023 10:36
  
Thank you for sharing your findings.
Faixan Lv1Posted 01 Aug 2023 14:54
  
good information
Jami Ullah Lv2Posted 01 Aug 2023 17:05
  
Thanks for sharing the specific use case of ES.
Newbie517762 Lv4Posted 01 Aug 2023 17:26
  
If you require any assistance, please do not hesitate to contact the Sangfor support team for my suggestion.
rivsy Lv5Posted 02 Aug 2023 15:15
  
thank you for the information
Siva Posted 02 Aug 2023 20:12
  
Dear Yakubi,

The reason for that is the Endpoint Secure uses different engines to determine a file is malicious.
The fact that you are able to scan the file as threat from Endpoint Secure shows that the file has been detected as a threat by one of the engine. (Definitely not Engine Zero, because as you can see from the Virus Total results it shows not detected by Engine Zero).

7302064ca4708c7370.png

I Can Help:

Change

Trending Topics

Board Leaders