SONAR Does not quarantine\delete malicious files found on network drives
search cancel

SONAR Does not quarantine\delete malicious files found on network drives

book

Article ID: 191790

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

With the option "Scan files on remote computers" enabled, a client will not quarantine\delete a SONAR detected file on the network drive. 
No detection is triggered and there is no evidence of the activity in the logs.

Environment

Component : SONAR
Network drive source machine is not scanned with SEP AV or SONAR, or does not have it installed.


Cause

See TechDocs regarding SONAR
"SONAR looks for worms such as Sality, which infects network drives.
Sality is a type of malware that infects files on Microsoft Windows systems and spreads through removable drives and network shares".

This is by design. 
The Network scanning feature of SONAR is built to scan for files that affect network drives, it does not have the ability to effectively delete and quarantine network files. Instead, it will block the file from running on the client machine. 

Resolution

If possible, Install SEP on the Network Drive host machine and enable SONAR, as per best practice.