<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="https://community.sophos.com/cfs-file/__key/system/syndication/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>How to interpret Event::Endpoint::CorePuaClean - manual cleanup needed or not?</title><link>https://community.sophos.com/intercept-x-endpoint/f/discussions/147986/how-to-interpret-event-endpoint-corepuaclean---manual-cleanup-needed-or-not</link><description>would like to understand when manual cleanup is needed via API events/alerts alone 
 
 this field in API events/alerts I am not clear on: 
 Event::Endpoint::CorePuaClean &amp;#39;result&amp;#39; 
 
 API RESULT UNDERSTOOD: 
 {&amp;quot;items&amp;quot;:[{&amp;quot;descriptor&amp;quot;:&amp;quot;C:\\Users\\SOMEUSERNAME</description><dc:language>en-US</dc:language><generator>Telligent Community 12</generator><item><title>RE: How to interpret Event::Endpoint::CorePuaClean - manual cleanup needed or not?</title><link>https://community.sophos.com/thread/548711?ContentTypeID=1</link><pubDate>Fri, 15 Nov 2024 14:53:26 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:dc67d610-b0f6-477d-bcef-8e008fe2b57f</guid><dc:creator>Robert_Smith</dc:creator><description>&lt;p&gt;documentation does not appear to explain the result piece (&amp;quot;result: SUCCESS&amp;quot; and&amp;nbsp;&amp;quot;result: NOT_FOUND&amp;quot; seem mutually exclusive)&lt;/p&gt;
&lt;table border="1"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td colspan="1" rowspan="1"&gt;&lt;code&gt;Event::Endpoint::CorePuaClean&lt;/code&gt;&lt;/td&gt;
&lt;td colspan="1" rowspan="1"&gt;PUA cleaned up: &amp;#39;&amp;#39;{2}&amp;#39;&amp;#39; &amp;quot;at &amp;#39;&amp;#39;{1}&amp;#39;&amp;#39;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: How to interpret Event::Endpoint::CorePuaClean - manual cleanup needed or not?</title><link>https://community.sophos.com/thread/548709?ContentTypeID=1</link><pubDate>Fri, 15 Nov 2024 14:42:22 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:d7f61a3a-022c-4025-a85e-f1217de60c6f</guid><dc:creator>Harshil_S</dc:creator><description>&lt;p&gt;Hello&amp;nbsp;&lt;a href="/members/robert_5f00_smith"&gt;Robert_Smith&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;/p&gt;
&lt;p&gt;The Sophos Central API will contain all the information, and this article will help you to understand what event results relate to.&lt;/p&gt;
&lt;p&gt;&lt;a href="https://support.sophos.com/support/s/article/KBA-000006285?language=en_US"&gt;Sophos Central Admin: Event types and descriptions for Sophos Central API&lt;/a&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: How to interpret Event::Endpoint::CorePuaClean - manual cleanup needed or not?</title><link>https://community.sophos.com/thread/548708?ContentTypeID=1</link><pubDate>Fri, 15 Nov 2024 14:31:41 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:16767ef9-8af0-40fb-8028-a7d30c699564</guid><dc:creator>Robert_Smith</dc:creator><description>&lt;p&gt;sometimes all I have is API&lt;/p&gt;
&lt;p&gt;&lt;span&gt;based on &amp;quot;In general&amp;quot; and &amp;quot;suggest checking on the central&amp;quot;, API alone does not sound like a reliable way to determine if threat was cleaned up successfully&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;span&gt;It sounds like I MUST assume worst case and tell my customer manual cleanup may be needed every time i do not see &amp;quot;result: SUCCESS or result: DELETED&amp;quot;&lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item><item><title>RE: How to interpret Event::Endpoint::CorePuaClean - manual cleanup needed or not?</title><link>https://community.sophos.com/thread/548674?ContentTypeID=1</link><pubDate>Fri, 15 Nov 2024 07:29:55 GMT</pubDate><guid isPermaLink="false">4be5eb7d-caa4-4ff5-8e60-8f9463545a35:79464403-9384-4945-982e-4afb216e7583</guid><dc:creator>Harshil_S</dc:creator><description>&lt;p&gt;Hello &lt;a href="/members/robert_5f00_smith"&gt;Robert_Smith&lt;/a&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;In general, if the Endpoint is unable to clean the threat or malware, then it raises an alert for manual cleanup. To verify the API result, I suggest checking on the central and co-relating the event coming from the API and the event appearing on central.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;</description></item></channel></rss>