Troubleshooting Guide
v2602
Search this version
Troubleshooting Guide
Troubleshooting Guide
Title
Message
Create new category
What is the title of your new category?
Edit page index title
What is the title of the page index?
Edit category
What is the new title of your category?
Edit link
What is the new title and URL of your link?
Troubleshooting Guide for Cybereason ActiveProbe Issues
AI Tools
Summarize Page
Copy Markdown
Open in ChatGPT
Open in Claude
This document aims to help users troubleshoot Cybereason ActiveProbe issues on macOS.
Issues
Real-time protection is not enabled

No successful scan recently

This guide provides quick checks that users can perform directly on the endpoint. The results help:
- You confirm the current Cybereason status on the device.
- Our team determine whether the MetaDefender Endpoint support package logs may have rotated when the issue happened.
Troubleshooting Guide
Real-time protection is not enabled
To troubleshoot this issue from the endpoint, please verify the following to ensure MetaDefender Endpoint can retrieve the correct status from Cybereason:
- Confirm Cybereason real-time protection processes are running
- Open Activity Monitor on the Mac
- In the search box, type
cybereason - Verify that the main Cybereason processes are present and running. If they are not running, please restart the Cybereason service or reboot the device, then check again.

Verify the device has network connectivity
- Open Terminal.
- Run the following command:
ping google.com - Confirm that you see replies (not “host unreachable” or timeouts). If there is no network connectivity, please resolve the network issue and then recheck the real-time protection status in MetaDefender Endpoint.
Verify the Cybereason configuration flag
- On the endpoint, open the file:
/usr/local/cybereason/config.plist - Locate the setting:
am.toggerValue - Confirm that:
am.toggerValue = 1
- On the endpoint, open the file:

No successful scan recently
MetaDefender Endpoint reads the last full scan information from the following file on the endpoint:/usr/local/cybereason/av_status.json
Follow the steps below:
- Check the
lastFullScanfield- Open the file:
/usr/local/cybereason/av_status.json - Interpret the value:
- If
lastFullScancontains a valid date/time, that is the last full scan Cybereason reports to MDE. - If
lastFullScanis empty or missing, Cybereason has no record of a completed full scan on this device.
- If
- Open the file:

- Trigger a new full scan if lastFullScan is empty or missing:
- Start a full scan from the Cybereason Dashboard on the endpoint (Contact Cybereason Admin).
- Wait for the full scan to complete.
- After completion, verify that
lastFullScaninav_status.jsonis now populated. - Click “Recheck” on the MetaDefender Endpoint tray icon and confirm the “Last successful scan” updates.
According to the vendor, the lastFullScan field is reset every time Cybereason ActiveProbe is upgraded to a newer version. This means:
- After an upgrade,
lastFullScanmay appear empty or show an older value. - A new full scan must be run after each upgrade to repopulate this field and allow MDE to show an up-to-date “Last successful scan” status.
Type to search, ESC to discard
Type to search, ESC to discard
Type to search, ESC to discard
Last updated on
Was this page helpful?
Discard Changes
Do you want to discard your current changes and overwrite with the template?
Archive Synced Block
Message
Create new Template
What is this template's title?
Delete Template
Message
