Você está na página 1de 3

The information contained herein is Petars study material and the accuracy is not completely guaranteed.

General Acronyms - McAfee

ePO - ePolicy Orchestrator


SIEM - Security Information and Event Management
IPS - Intrusion Prevention System
ESM - Enterprises Security Manager
TIE - Threat Intelligence Exchange
GTI - Global Threat Intelligence
ATD - Advanced Threat Defence
SaaS - Software as a Service

Area of vulnerability
Product to help

Traffic entering a network:


Network Security Platform (IPS), and ATD.

Cloud
GTI (Global Threat Intelligence) and SaaS

Databases and Server Farm


Products managed by ePO for servers

Perimeter-inbound/outbound traffic
Network Data Loss Prevention and Web Protection

Network and Security Management


Threat Intelligence Exchange, ePolicy Orchestrator, Enterprise Security Manager, McAfee
Active Response

Endpoints
Endpoint Security 10

Product, and how it works with ATD

ePO and GTI


Work with ATD to gather file signatures and reputation-based darts; suspicions files are then isolated
by ATD and ruin in a virtual sandbox.

ePO and TIE


Work with ATD to learn and adapt to fix any associations with malicious files across the network

Web Protection and IPS


For files run in a sandbox environment and found to be malicious, ATD sends messages to these
products to instantly lock down communications back to the hacker's host computer

TIE (Threat Intelligence Exchange) is like a mini-GTI (Global Threat Intelligence) in an organization,
inspecting and broadcasting locked down intelligence across the network.

ASCI (Asskey) - Agent-to-Server Communication Interval

ASSC - Agent-to-Server Secure Communication


(Keys, come in pairs, one is Master Key)

SuperAgent:

Agent: An agent is ----

System: A system is a managed machine, that can be a server, workstation, laptop or an appliance.

Managed
Policy
Policy Application Rules (check)

MER Tool: Minimum Escalation Requirements Tool

ENS - Endpoint Security (McAfee)

Firewall Group
no actions in group

NSP [en-es-pee] - Network Security Platform

GAM [] - Gateway Anti-Maleware


Down selectors / static analysis opposite of sandbox/dynamic analysis

RMM4 - Remote management module v4 (works with Integrated BMC Web Console

MWG - McAfee Web Gateway

SEF - Standard event format; used to forward events from ESM to a ERC (Reciever) on a different ESM,
or from a third party to a Reciever.

MEF - McAfee Event Format

Você também pode gostar