All Things Symantec

This post contains information on my research into Symantec Endpoint Protection logs, quarantine, and ccSubSDK files. Content will be updated regularly.

Log Line

This is an important piece to understand because it can be found in the entries of the Antivirus Management Plug-in log, Client Management Security log, Client Management System log, Daily Antivirus logs, and the quarantine files.

Symantec Endpoint Protection Logs

Symantec Management Client (SMC) does not show the entire contents of the log. smc.exe has an -exportlog command line switch where you can select a log type to export.  Log_type numbers are as follows:

  • 0 = System Log
  • 1 = Security Log
  • 2 = Traffic Log
  • 3 = Packet Log
  • 4 = Control Log 

These numbers also correlate to an entry in the header of the logs found in the following locations:

Windows: 

C:\ProgramData\Symantec\Symantec Endpoint Protection\CurrentVersion\Data\Logs.

Linux:

/var/symantec/Logs/syslog.log

  • 0 = syslog.log
  • 1 = seclog.log
  • 2 = tralog.log
  • 3 = rawlog.log
  • 4 = processlog.log

Log File Structure

Submission Engine

"Symantec Endpoint Protection clients automatically submit pseudonymous information about detections, network, and configuration to Symantec Security Response. Symantec uses this pseudonymous information to address new and changing threats as well as to improve product performance. Pseudonymous data is not directly identified with a particular user.

The detection information that clients send includes information about antivirus detections, intrusion prevention, SONAR, and file reputation detections." [1]

Info for Endpoint Protection in the registry