<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AMP - False Positive in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/amp-false-positive/m-p/3822272#M3087</link>
    <description>&lt;P&gt;If that is IOC event then it can't be excluded or whitelisted, only muted. To suppress these alerts it is required to globally mute the IOC in the dashboard. To do so login to your AMP console, go to Dashboard &amp;gt; navigate to bottom &amp;gt; Compromise Events Types &amp;gt; you will see a bell icon &amp;gt; find the IOC you would like to mute and click that. More details:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.amp.cisco.com/en/A4E/AMP%20for%20Endpoints%20User%20Guide.pdf#G3.1750717" target="_blank"&gt;https://docs.amp.cisco.com/en/A4E/AMP%20for%20Endpoints%20User%20Guide.pdf#G3.1750717&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Disadvantage: mute of such event, will trigger mute as well for not false-positives.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps,&lt;BR /&gt;-Wojciech&lt;/P&gt;</description>
    <pubDate>Tue, 19 Mar 2019 18:13:58 GMT</pubDate>
    <dc:creator>Wojciech Cecot</dc:creator>
    <dc:date>2019-03-19T18:13:58Z</dc:date>
    <item>
      <title>AMP - False Positive</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-false-positive/m-p/3816562#M3083</link>
      <description>&lt;P&gt;So I have a user using excel with a macro/script and AMP keeps flagging&amp;nbsp;&lt;STRONG&gt;VBA.ObfDldr.1.Gen&lt;/STRONG&gt;&amp;nbsp;How can I whitelist this file so it's not alerting 100x a day. The hash changes when they use the file.&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:08:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-false-positive/m-p/3816562#M3083</guid>
      <dc:creator>LoTeK</dc:creator>
      <dc:date>2020-02-21T05:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: AMP - False Positive</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-false-positive/m-p/3822272#M3087</link>
      <description>&lt;P&gt;If that is IOC event then it can't be excluded or whitelisted, only muted. To suppress these alerts it is required to globally mute the IOC in the dashboard. To do so login to your AMP console, go to Dashboard &amp;gt; navigate to bottom &amp;gt; Compromise Events Types &amp;gt; you will see a bell icon &amp;gt; find the IOC you would like to mute and click that. More details:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.amp.cisco.com/en/A4E/AMP%20for%20Endpoints%20User%20Guide.pdf#G3.1750717" target="_blank"&gt;https://docs.amp.cisco.com/en/A4E/AMP%20for%20Endpoints%20User%20Guide.pdf#G3.1750717&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Disadvantage: mute of such event, will trigger mute as well for not false-positives.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps,&lt;BR /&gt;-Wojciech&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2019 18:13:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-false-positive/m-p/3822272#M3087</guid>
      <dc:creator>Wojciech Cecot</dc:creator>
      <dc:date>2019-03-19T18:13:58Z</dc:date>
    </item>
  </channel>
</rss>

