This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Generating Test Alerts

Hi All,

I am trying to generate a couple of Sophos alerts for testing purposes and having real trouble making them happen!

We are monitoring the Windows event log (in this case Windows XP) and setting alerts for certain items in our system monitoring tool.  Generating virus alerts is easy using the supplied tool but does anyone know how to generate a "Suspicious Behavior" alert or a "Corrupt file found" warning?

For the corrupt file I have tried various ways of corrupting a file - changing the extension, modifying bits in the middle of the file and so on, Windows / Word / whatever report it is corrupt but Sophos always manages to successfully scan it.

A lot of searching and asking around has yet to find anything that works - any ideas or is the only thing people test the AV alert?

Thanks

sTv

:35407


This thread was automatically locked due to age.
Parents
  • In case anyone looks for how to do this in the future.

    I managed to generate a corrupt file alert as well.

    To do this get the autoit utility Jak mentioned earlier and install it.

    Create a Windows PowerPoint presentation called corruptfile.ppt (so in the older .ppt format)

    Rename the file from .ppt to .au3

    Right click and edit the file in autoit.

    Remove some of the symbols and NUL special characters from the file.  Add in @ symbols, text characters etc in random places (not among any text that may be part of your presentation!)

    Save the file.

    Rename it back to .ppt

    RIght click and scan with Sophos AV to generate an event in the Application Event Log stating the file was corrupt.

    Thanks Jak - you solved both issues!

    :35509
Reply
  • In case anyone looks for how to do this in the future.

    I managed to generate a corrupt file alert as well.

    To do this get the autoit utility Jak mentioned earlier and install it.

    Create a Windows PowerPoint presentation called corruptfile.ppt (so in the older .ppt format)

    Rename the file from .ppt to .au3

    Right click and edit the file in autoit.

    Remove some of the symbols and NUL special characters from the file.  Add in @ symbols, text characters etc in random places (not among any text that may be part of your presentation!)

    Save the file.

    Rename it back to .ppt

    RIght click and scan with Sophos AV to generate an event in the Application Event Log stating the file was corrupt.

    Thanks Jak - you solved both issues!

    :35509
Children
No Data