> Source: [sk169753](https://support.checkpoint.com/results/sk/sk169753)

# sk169753 - Endpoint Anti-Malware 'Detect Mode' 

| Property | Value |
|----------|-------|
| Solution ID | sk169753 |
| Date Created | 2020-10-07 |
| Last Modified | 2021-07-11 |
| Technical Level | General |
| Products | Endpoint Security |
| Versions | Cloud, E89.X, E88.X |
| OS | Windows |
| Platform | Intel/PC |

## Solution

Scope
-----

When Anti-Malware runs in the "Detect Mode"

* Files are scanned.
* Detected infections are not cured, not blocked, not terminated.
* Detected infections appear in the client UI, sent to the server and EFR.

**Note** - The "Detect Mode" leaves the PC in a compromised state.

How to enable?
--------------

**In R81 (On-Premises) and lower versions:**

1. In SmartEndpoint, navigate to the **Policy** tab.
2. In the **Anti-Malware** row, find the **Comment** column.
3. Right-click the **Comment** cell and add this phrase to the comment:  
   *Anti-Malware Detect Mode*

**In R81 (Cloud) or R81.10 (On-Premises) and higher versions:**

Refer to the Endpoint Management Administration Guide for your version.

* [Endpoint Security Homepage](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk117536)
* [Harmony Endpoint Administration Guide](https://sc1.checkpoint.com/documents/Infinity_Portal/WebAdminGuides/EN/Harmony-Endpoint-Admin-Guide/Default.htm)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
