Athena EPP (Endpoint Protection Platform)

Athena EPP (formerly Sangfor Endpoint Secure) integrates NGAV, EDR, and endpoint management into a single, powerful solution for comprehensive endpoint protection.
{{ $t('productDocDetail.guideClickSwitch') }}
{{ $t('productDocDetail.know') }}
{{ $t('productDocDetail.dontRemind') }}
6.0.4R4
{{sendMatomoQuery("Athena EPP (Endpoint Protection Platform)","Detection Policies")}}

Detection Policies

{{ $t('productDocDetail.updateTime') }}: 2025-12-30

4.6.2.1File Hashes

File hashes can help you quickly respond to false positive and false negative security events, thereby improving O&M efficiency.

Go to Policies > Detection Policies > File Hashes, as shown in the following figure.

You can set the action to take for specified files. Supported actions are Alert and Fix, Alert, and Allow.

Alert and Fix: A false negative threat will be fixed and an alert will be given for the threat.

Alert: Only an alert is given for the threat.

Allow: A false positive threat is allowed.

4.6.2.2WebShell Directories

You can specify web directories for detecting web shells on web servers.