“Passed a potential security risk” appears on the Virus/Malware Logs-If you want to enable quarantine :

Süleyman Çelik
2 min readMar 12, 2021

--

The scan action “Passed a potential security risk” appears when the product detects a probable virus/malware while it is using ActiveAction.

ActiveAction is a set of pre-configured scan actions that identifies virus/malware types and provides suggested actions according to how each type invades a computer system or environment. By default, “Pass” is the action for probable virus/malware. This means that due to aggressiveness of the detection, Security Solution will perform no action on the possibly infected file but instead records the virus/malware detection in the logs. The file stays where it is located.

DETAILS

Configure your product to take action on probable virus/malware.

If you want to enable quarantine ;

  • Log on to the OfficeScan management console.
  • Go to Agents > Agent Management.
  • In the Agent Tree, select the OfficeScan Server/Domain/Computer.
  • Go to Settings > Scan Settingsand select the scan type.
  • Manual Scan Settings
  • Real-time Scan Settings
  • Scheduled Scan Settings
  • Scan Now Settings
  • Go to Action tab.
  • Under ActiveAction, put a check on “Customize action for probable virus/malware” and select the corresponding scan action.
  • Alternatively, you can select “Use a specific scan action for each virus/malware type” and configure the scan action for probable malware.

--

--

Süleyman Çelik
Süleyman Çelik

Written by Süleyman Çelik

Network Security Engineer, SOC-Siem Engineer, Cyber Security Researcher, Vulnerability Management Specialist | CEH | CNSS

No responses yet