<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Doubt with AMP dynamic analysis in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/doubt-with-amp-dynamic-analysis/m-p/3752805#M222</link>
    <description>&lt;P&gt;Thank you so much yogdhanu for clarify my doubt!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards!!&lt;/P&gt;</description>
    <pubDate>Mon, 26 Nov 2018 14:52:18 GMT</pubDate>
    <dc:creator>Ariel0092</dc:creator>
    <dc:date>2018-11-26T14:52:18Z</dc:date>
    <item>
      <title>Doubt with AMP dynamic analysis</title>
      <link>https://community.cisco.com/t5/endpoint-security/doubt-with-amp-dynamic-analysis/m-p/3751997#M219</link>
      <description>&lt;P&gt;HI everyone i have a doubt with the action of dynamic analysis on the FMC, i have read and hear some folks who says that the files(for example a .exe) are never send to the cloud, only a hash sha256, and from my undertstanding this is what the spero engine does, but with the dynamic analysis the documentation stays that the file with a disposition of unknown is submitted to threat grid a.k.a. sandboxing for analysis, so my question/doubt is if a user downloads a file .exe with unknown disposition does the firepower send the entire file for sandboxing or sends a sha256?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope you can understand my question and clarify me this concepts .&lt;/P&gt;
&lt;P&gt;Thanks and Best regards!&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:07:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/doubt-with-amp-dynamic-analysis/m-p/3751997#M219</guid>
      <dc:creator>Ariel0092</dc:creator>
      <dc:date>2020-02-21T05:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: Doubt with AMP dynamic analysis</title>
      <link>https://community.cisco.com/t5/endpoint-security/doubt-with-amp-dynamic-analysis/m-p/3752679#M221</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dynamic analysis or sandboxing for unknown file does require full file to be submitted which is done on FMC.&lt;/P&gt;
&lt;P&gt;But for known files only SHA query is done and Threatgrid would reply back with threat score and AMP cloud would let know the disposition like malicious, clean or unknown.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps,&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;</description>
      <pubDate>Mon, 26 Nov 2018 11:51:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/doubt-with-amp-dynamic-analysis/m-p/3752679#M221</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2018-11-26T11:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Doubt with AMP dynamic analysis</title>
      <link>https://community.cisco.com/t5/endpoint-security/doubt-with-amp-dynamic-analysis/m-p/3752805#M222</link>
      <description>&lt;P&gt;Thank you so much yogdhanu for clarify my doubt!!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best regards!!&lt;/P&gt;</description>
      <pubDate>Mon, 26 Nov 2018 14:52:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/doubt-with-amp-dynamic-analysis/m-p/3752805#M222</guid>
      <dc:creator>Ariel0092</dc:creator>
      <dc:date>2018-11-26T14:52:18Z</dc:date>
    </item>
  </channel>
</rss>

