> Source: [sk183552](https://support.checkpoint.com/results/sk/sk183552)

# sk183552 - Threat Emulation Reports are Not Generated - Understanding File Protection Flow

| Property | Value |
|----------|-------|
| Solution ID | sk183552 |
| Date Created | 2025-06-23 |
| Last Modified | 2025-07-07 |
| Technical Level | Advanced |
| Products | Endpoint Security |
| Versions | E89.X, E88.X |

## Symptoms

- Threat Emulation (TE) reports are not generated for certain files, even though malicious activity is detected by the Endpoint Security solution.

## Cause

Threat Emulation generates a report only when a file successfully passes through all preceding protection layers without being flagged as malicious. If another component (such as File Reputation or SA) detects and blocks the file beforehand, Threat Emulation is not triggered, and no report is generated.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
