<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False positives from Cisco AMP in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/false-positives-from-cisco-amp/m-p/3750747#M227</link>
    <description>&lt;P&gt;Global&amp;nbsp;passing is what I'm interested in because I'm not a Cisco customer. I'm the&amp;nbsp;creator of the file that is being flagged.&lt;/P&gt;
&lt;P&gt;How would I go about opening a TAC case?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Aside from&amp;nbsp;focusing on a specific file, is there a way to submit a signature to Cisco so that any file signed with that signature can pass as not malicious?&lt;/P&gt;</description>
    <pubDate>Wed, 21 Nov 2018 13:54:34 GMT</pubDate>
    <dc:creator>tyler.johnson</dc:creator>
    <dc:date>2018-11-21T13:54:34Z</dc:date>
    <item>
      <title>False positives from Cisco AMP</title>
      <link>https://community.cisco.com/t5/endpoint-security/false-positives-from-cisco-amp/m-p/3749432#M225</link>
      <description>&lt;P&gt;We have a downloadable executable that is being flagged.&amp;nbsp;It is a signed Windows executable. Is it possible to register with Cisco as a whitelisted vendor so that executables with our signature don't trigger false positives? Is there any other option to prevent&amp;nbsp;alarming the end user?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:06:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/false-positives-from-cisco-amp/m-p/3749432#M225</guid>
      <dc:creator>tyler.johnson</dc:creator>
      <dc:date>2020-02-21T05:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: False positives from Cisco AMP</title>
      <link>https://community.cisco.com/t5/endpoint-security/false-positives-from-cisco-amp/m-p/3750611#M226</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can add the SHA value of that to whitelist in your policy. If you believe the file is not malicious at all and should not be marked malicious globally, please open TAC case to request for FP analysis.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope it helps,&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 10:43:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/false-positives-from-cisco-amp/m-p/3750611#M226</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2018-11-21T10:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: False positives from Cisco AMP</title>
      <link>https://community.cisco.com/t5/endpoint-security/false-positives-from-cisco-amp/m-p/3750747#M227</link>
      <description>&lt;P&gt;Global&amp;nbsp;passing is what I'm interested in because I'm not a Cisco customer. I'm the&amp;nbsp;creator of the file that is being flagged.&lt;/P&gt;
&lt;P&gt;How would I go about opening a TAC case?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Aside from&amp;nbsp;focusing on a specific file, is there a way to submit a signature to Cisco so that any file signed with that signature can pass as not malicious?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2018 13:54:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/false-positives-from-cisco-amp/m-p/3750747#M227</guid>
      <dc:creator>tyler.johnson</dc:creator>
      <dc:date>2018-11-21T13:54:34Z</dc:date>
    </item>
    <item>
      <title>Re: False positives from Cisco AMP</title>
      <link>https://community.cisco.com/t5/endpoint-security/false-positives-from-cisco-amp/m-p/3751307#M228</link>
      <description>&lt;P&gt;Hello Tyler&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;If you think the file is not malicious then you can add it to the whitelist option and you can allow this file in your environment. But if you are looking for a global passing, then Cisco TALOS will have to review the file and update the disposition only if the file is not malicious or not showing any high threat score. If the file is not showing any malicious behaviour then TALOS will do the needful. As an initial step you can open the case with Cisco TAC and they will involve the TALOS team to verify the same. Please provide the file sample&amp;nbsp;along with the&amp;nbsp;sha value while opening the case with Cisco TAC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2018 09:10:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/false-positives-from-cisco-amp/m-p/3751307#M228</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2018-11-22T09:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: False positives from Cisco AMP</title>
      <link>https://community.cisco.com/t5/endpoint-security/false-positives-from-cisco-amp/m-p/3751388#M229</link>
      <description>&lt;P&gt;How do I open a case with Cisco TAC?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried calling Cisco support on the phone and they wouldn't help since I'm not a Cisco customer.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Nov 2018 12:28:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/false-positives-from-cisco-amp/m-p/3751388#M229</guid>
      <dc:creator>tyler.johnson</dc:creator>
      <dc:date>2018-11-22T12:28:20Z</dc:date>
    </item>
  </channel>
</rss>

