{"id":426,"date":"2012-09-23T16:15:53","date_gmt":"2012-09-23T14:15:53","guid":{"rendered":"http:\/\/sccmfaq.wordpress.com\/?p=426"},"modified":"2012-09-23T16:15:53","modified_gmt":"2012-09-23T14:15:53","slug":"sccm-2012-maware-detection-e-mail-alert","status":"publish","type":"post","link":"https:\/\/blog.hosebei.ch\/?p=426","title":{"rendered":"SCCM 2012 &#8211; Malware detection E-Mail Alert"},"content":{"rendered":"<p>In System Center 2012 Configuration Manager, it is easy to configure a E-Mail Alert, when malware is recognized on a system which is protected by System Center Endpoint Protection.<\/p>\n<p>Your first step, is to configure a proper connection to send the E-Mail. Navigate to your Central Administration or Primary Site, and\u00a0open Configure Site Components to chose Email Notification:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2012\/09\/email-notification-01.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-428\" title=\"Email Notification 01\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2012\/09\/email-notification-01.png?w=300\" alt=\"\" width=\"300\" height=\"95\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2012\/09\/email-notification-01.png 987w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2012\/09\/email-notification-01-300x95.png 300w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2012\/09\/email-notification-01-768x244.png 768w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a>Configure your settings and send a Test-Mail:<!--more--><br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2012\/09\/email-notification-02.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-429\" title=\"Email Notification 02\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2012\/09\/email-notification-02.png?w=297\" alt=\"\" width=\"297\" height=\"300\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2012\/09\/email-notification-02.png 573w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2012\/09\/email-notification-02-298x300.png 298w\" sizes=\"auto, (max-width: 297px) 100vw, 297px\" \/><\/a>If you received the Test-Mail, go further, and configure alerting on Collections, open properties for the collection where you want to get a mail, when malware is found:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2012\/09\/email-notification-03.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-430\" title=\"Email Notification 03\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2012\/09\/email-notification-03.png?w=300\" alt=\"\" width=\"300\" height=\"264\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2012\/09\/email-notification-03.png 638w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2012\/09\/email-notification-03-300x265.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a>After this step, you can configure the conditions, but in this case, i just used standard values. By clicking on OK, the alerting is possible, but not activated yet. To do this, click on Monitoring, and open the tree &#8220;Alerts&#8221;, chose &#8220;Create Subscripton, to active your Email Alert:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2012\/09\/email-notification-04.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-432\" title=\"Email Notification 04\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2012\/09\/email-notification-04.png?w=121\" alt=\"\" width=\"121\" height=\"300\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2012\/09\/email-notification-04.png 297w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2012\/09\/email-notification-04-121x300.png 121w\" sizes=\"auto, (max-width: 121px) 100vw, 121px\" \/><\/a>The Wizard appears, and have to select your Malware Alert previous generated. As you might see, you can configure the subscription for more than only one address:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2012\/09\/email-notification-05.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-433\" title=\"Email Notification 05\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2012\/09\/email-notification-05.png?w=258\" alt=\"\" width=\"258\" height=\"300\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2012\/09\/email-notification-05.png 510w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2012\/09\/email-notification-05-258x300.png 258w\" sizes=\"auto, (max-width: 258px) 100vw, 258px\" \/><\/a>So, but now, I would like to test, if it&#8217;s really works. No worries, just before you download a real virus, just take the eicar,\u00a0a Test Malware from the Microsoft recommended website (<a href=\"http:\/\/www.microsoft.com\/security\/portal\/Threat\/Encyclopedia\/Glossary.aspx#e\">http:\/\/www.microsoft.com\/security\/portal\/Threat\/Encyclopedia\/Glossary.aspx#e<\/a>):<br \/>\n<a href=\"http:\/\/www.eicar.org\/86-0-Intended-use.html\">http:\/\/www.eicar.org\/86-0-Intended-use.html<\/a><\/p>\n<p>When you try to run the file, shortenly after, you will receive your email, and you can check your SCEP Log:<br \/>\n<a href=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2012\/09\/email-notification-06.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-medium wp-image-434\" title=\"Email Notification 06\" src=\"http:\/\/hosebei.wordpress.com\/wp-content\/uploads\/2012\/09\/email-notification-06.png?w=300\" alt=\"\" width=\"300\" height=\"273\" srcset=\"https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2012\/09\/email-notification-06.png 767w, https:\/\/blog.hosebei.ch\/wp-content\/uploads\/2012\/09\/email-notification-06-300x274.png 300w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/a>I hope this helps.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In System Center 2012 Configuration Manager, it is easy to configure a E-Mail Alert, when malware is recognized on a system which is protected by System Center Endpoint Protection. Your first step, is to configure a proper connection to send the E-Mail. Navigate to your Central Administration or Primary Site, and\u00a0open Configure Site Components to [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15,18,19],"tags":[],"class_list":["post-426","post","type-post","status-publish","format-standard","hentry","category-configmgr","category-endpoint-protection","category-general"],"_links":{"self":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/426","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=426"}],"version-history":[{"count":0,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=\/wp\/v2\/posts\/426\/revisions"}],"wp:attachment":[{"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=426"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=426"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.hosebei.ch\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=426"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}