Testing and Analyzing Analytics: FlashDownloadNotSignedByAdobe - Jamf Protect Evaluation Guide

Jamf Protect Evaluation Guide

Solution
Application
Content Type
Technical Documentation
Utilities & Services
ft:locale
en-US

Follow the steps below to test the FlashDownloadNotSignedByAdobe analytic.

Requirements

If using a virtual machine, take a snapshot to revert back to at the end of this simulation.

  1. Download the file located here (https://themittenmac.com/wp-content/uploads/flash.dmg). This file is a simple dmg with the word "Flash" in the file name. It is not signed by Adobe and will therefore trigger a detection.
    After completing the above testing steps a new alert titled FlashDownloadNotSignedByAdobe can be expected inside Jamf Protect Cloud.
  2. Open and review the FlashDownloadNotSignedByAdobe alert. The most interesting data points when analyzing this alert are:
    • Summary > Download Event Details > Path: The file path of the downloaded .dmg.

    • Summary > Download Event Details > Download From: Provides information about where the file was downloaded from.

    • Files > Signing Info: Provides indication that the file was not signed by Adobe.

    In a real world scenario, investigation of this alert should begin with examining the dmg that was downloaded and investigating where it was downloaded from.

  3. If a virtual machine snapshot was taken prior to completing this test scenario the easiest cleanup method is to revert to the snapshot.