疑難排解 Microsoft Defender 的 Endpoint live 回應問題Troubleshoot Microsoft Defender for Endpoint live response issues

適用於:Applies to:

想要體驗 Defender for Endpoint?Want to experience Defender for Endpoint? 注册免費試用版。Sign up for a free trial.

此頁面提供疑難排解 live response 問題的詳細步驟。This page provides detailed steps to troubleshoot live response issues.

在即時回應會話期間無法存取檔File cannot be accessed during live response sessions

當您嘗試在 live response session 期間採取動作時,您會遇到錯誤訊息,指出無法存取檔案,您必須使用下列步驟來解決問題。If while trying to take an action during a live response session, you encounter an error message stating that the file can't be accessed, you'll need to use the steps below to address the issue.

  1. 複製下列腳本代碼片段,並將它儲存為 PS1 檔案:Copy the following script code snippet and save it as a PS1 file:

    $copied_file_path=$args[0] 
    $action=Copy-Item $copied_file_path -Destination $env:TEMP -PassThru -ErrorAction silentlyContinue
    
    if ($action){
         Write-Host "You copied the file specified in $copied_file_path to $env:TEMP Succesfully"
    }
    
    else{
        Write-Output "Error occoured while trying to copy a file, details:"
        Write-Output  $error[0].exception.message
    
    }
    
  2. 將腳本新增至 live 回應文件庫。Add the script to the live response library.

  3. 以一個參數執行腳本:要複製之檔案的檔案路徑。Run the script with one parameter: the file path of the file to be copied.

  4. 流覽至您的 TEMP 資料夾。Navigate to your TEMP folder.

  5. 請執行您想要對複製的檔案採取的動作。Run the action you wanted to take on the copied file.

在初始連線期間緩慢即時回應會話或延遲Slow live response sessions or delays during initial connections

Live response 利用 Defender 在 Windows 中使用 WNS 服務的端點感應器註冊。Live response leverages Defender for Endpoint sensor registration with WNS service in Windows. 如果您有即時回應的連線問題,請確認下列詳細資料:If you are having connectivity issues with live response, confirm the following details:

  1. notify.windows.com 在您的環境中未遭到封鎖。notify.windows.com is not blocked in your environment. 如需詳細資訊,請參閱 Configure device proxy And Internet connectivity settingsFor more information, see, Configure device proxy and Internet connectivity settings.
  2. 未停用 WpnService (Windows 推播通知系統服務) 。WpnService (Windows Push Notifications System Service) is not disabled.

請參閱下列文章,以完全瞭解 WpnService 服務的行為和需求:Refer to the articles below to fully understand the WpnService service behavior and requirements: