File path in Endpoint Protection risk detection contains '>>' (double greater-than signs)
search cancel

File path in Endpoint Protection risk detection contains '>>' (double greater-than signs)

book

Article ID: 220957

calendar_today

Updated On:

Products

Endpoint Protection

Issue/Introduction

In Symantec Endpoint Protection (SEP) you receive a risk detection where the file path includes '>>' . 

Example;

File or Path: >>example_folder\newfolder\setup.exe

Cause

A ">>" in the file path indicates the detection occurred within a compressed file.  You may also see this symbol if the full path to the file exceeds 200 characters.

Resolution

This behavior is by design for detections within a compressed file and requires no action.

To view the path of the compressed file in detection use the below methods:

  • The notification event contains the complete file system folder path for detection.
  • You can get the details from the SEP client by checking the View Quarantine option and that should show you the original location.
  • You can also get the details by running a risk log from SEPM for that client machine.