<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom Detection in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/custom-detection/m-p/3890494#M109</link>
    <description>&lt;P&gt;You mentioned using an Audit Policy.&amp;nbsp; The file won't be quarantined if you're using an Audit policy, you will just get a notification that it would have been quarantined if the policy was set up to do so.&lt;/P&gt;</description>
    <pubDate>Mon, 15 Jul 2019 19:07:11 GMT</pubDate>
    <dc:creator>Matthew Franks</dc:creator>
    <dc:date>2019-07-15T19:07:11Z</dc:date>
    <item>
      <title>Custom Detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/custom-detection/m-p/3890416#M64</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;I would like to know why when I use a custom detection to quarantine a file, that file won't go to the quarantine folder and doesn't show me that the file was quarantined.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Even when I try to open the file again, the AMP shows me "&lt;SPAN&gt;not quarantined"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So, is it possible to quarantine a file using Audit policy for instance? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Because looks like is not.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:09:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/custom-detection/m-p/3890416#M64</guid>
      <dc:creator>Diego Leitao</dc:creator>
      <dc:date>2020-02-21T05:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/custom-detection/m-p/3890436#M74</link>
      <description>Did you add the Custom Detection to the policy under Management/Policies??&lt;BR /&gt;&lt;BR /&gt;You create it under Outbreak Control, but it has to be added to the policies.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 15 Jul 2019 17:00:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/custom-detection/m-p/3890436#M74</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2019-07-15T17:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/custom-detection/m-p/3890456#M95</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yeah, I did it but didn't work in that time.&lt;/P&gt;&lt;P&gt;But I think it's another problem.&lt;/P&gt;&lt;P&gt;I'm facing today a problem of delay on AMP.&lt;/P&gt;&lt;P&gt;Some events were reported later. So I think that the manual quarantine didn't work because of that, maybe the event will be reported later.&lt;/P&gt;&lt;P&gt;Anyway, thanks for your help&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2019 17:58:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/custom-detection/m-p/3890456#M95</guid>
      <dc:creator>Diego Leitao</dc:creator>
      <dc:date>2019-07-15T17:58:09Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/custom-detection/m-p/3890494#M109</link>
      <description>&lt;P&gt;You mentioned using an Audit Policy.&amp;nbsp; The file won't be quarantined if you're using an Audit policy, you will just get a notification that it would have been quarantined if the policy was set up to do so.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2019 19:07:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/custom-detection/m-p/3890494#M109</guid>
      <dc:creator>Matthew Franks</dc:creator>
      <dc:date>2019-07-15T19:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: Custom Detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/custom-detection/m-p/3890515#M120</link>
      <description>&lt;P&gt;So, is it not possible to manual quarantine a file if you are using an&amp;nbsp;&lt;SPAN&gt;Audit policy?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I know that automatic quarantine in a Auditi policy doesn't work, but I thought that you could do that manually.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2019 19:29:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/custom-detection/m-p/3890515#M120</guid>
      <dc:creator>Diego Leitao</dc:creator>
      <dc:date>2019-07-15T19:29:51Z</dc:date>
    </item>
  </channel>
</rss>

