<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AMP for endpoint can't block the packered WannaCry. in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-can-t-block-the-packered-wannacry/m-p/3431781#M3120</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Takahiro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apologies for the delay to respond. You can enroll in the Beta program using your AMP for Endpoints console by navigating to Management &amp;gt; Beta &amp;gt; Enroll. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 Feb 2018 07:47:38 GMT</pubDate>
    <dc:creator>emirolyu</dc:creator>
    <dc:date>2018-02-28T07:47:38Z</dc:date>
    <item>
      <title>AMP for endpoint can't block the packered WannaCry.</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-can-t-block-the-packered-wannacry/m-p/3431776#M3115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;AMP for endpoint seems to be not able to block the wannacry which is encrypted with packer tool.&lt;/P&gt;&lt;P&gt;Are there any workaround?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Repro-steps:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. get a wannacry from ThreatGrid or any other service&lt;/P&gt;&lt;P&gt;&lt;IMG alt="1.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/115452_1.png" style="height: 285px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. encrypt it with packer tool such as upx&lt;/P&gt;&lt;P&gt;&lt;IMG alt="2.png" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/115453_2.png" style="height: 139px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. open AMP console and enable TETRA feature.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="3.png" class="jive-image image-3" src="https://community.cisco.com/legacyfs/online/fusion/115454_3.png" style="height: 429px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4. Install the Connector.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;5. Scan the wannacry with AMP for endpoint. It is judged as no problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6. Run the wannacry. It works. Some programs such as WannaDecrypter are blocked. But encryption of user data complete.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="4.png" class="jive-image image-4" src="https://community.cisco.com/legacyfs/online/fusion/115455_4.png" style="height: 349px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:05:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-can-t-block-the-packered-wannacry/m-p/3431776#M3115</guid>
      <dc:creator>Tsunoda</dc:creator>
      <dc:date>2020-02-21T05:05:28Z</dc:date>
    </item>
    <item>
      <title>Re: AMP for endpoint can't block the packered WannaCry.</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-can-t-block-the-packered-wannacry/m-p/3431777#M3116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Takahiro Tsunoda,&lt;/P&gt;&lt;P&gt;Thank you for your screenshots and the repro-steps.&lt;/P&gt;&lt;P&gt;What version of the AMP for Endpoints connector are you running in this testing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 24 Feb 2018 19:49:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-can-t-block-the-packered-wannacry/m-p/3431777#M3116</guid>
      <dc:creator>emirolyu</dc:creator>
      <dc:date>2018-02-24T19:49:55Z</dc:date>
    </item>
    <item>
      <title>Re: AMP for endpoint can't block the packered WannaCry.</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-can-t-block-the-packered-wannacry/m-p/3431778#M3117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Evgeny,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your reply.&lt;/P&gt;&lt;P&gt;The version of connector I tested is 6.0.7.10670.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Takahiro&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Feb 2018 03:30:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-can-t-block-the-packered-wannacry/m-p/3431778#M3117</guid>
      <dc:creator>Tsunoda</dc:creator>
      <dc:date>2018-02-26T03:30:23Z</dc:date>
    </item>
    <item>
      <title>Re: AMP for endpoint can't block the packered WannaCry.</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-can-t-block-the-packered-wannacry/m-p/3431779#M3118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Takahiro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for sharing further details of your testing. Did you see a Cloud IOC fire in the AMP Console? I would expect that to happen as the minimum and in a realistic scenario, the infection could be prevented by one of the "new" engines, that are a part of this connector version. For real-time ransomware blocking, there's going to be a beta of one more component available soon, that is highly effective at addressing the problem of ransomware generically (file encryption behavior observed, initiating process blocked; with an ability to exclude benign processes). A notification about the Beta will be posted to the AMP Console and you would receive an email notification if that's enabled on your console.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Feb 2018 14:00:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-can-t-block-the-packered-wannacry/m-p/3431779#M3118</guid>
      <dc:creator>emirolyu</dc:creator>
      <dc:date>2018-02-26T14:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: AMP for endpoint can't block the packered WannaCry.</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-can-t-block-the-packered-wannacry/m-p/3431780#M3119</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Evgeny,&lt;/P&gt;&lt;P&gt;I checked the trajectry. IOC have been fired. But wannacry main file was not quarantined.&lt;/P&gt;&lt;P&gt;I was not able to find the information about beta. How can I use it?&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="115497" alt="trajectry.png" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/115497_trajectry.png" style="height: 293px; width: 620px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Feb 2018 16:43:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-can-t-block-the-packered-wannacry/m-p/3431780#M3119</guid>
      <dc:creator>Tsunoda</dc:creator>
      <dc:date>2018-02-26T16:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: AMP for endpoint can't block the packered WannaCry.</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-can-t-block-the-packered-wannacry/m-p/3431781#M3120</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Takahiro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apologies for the delay to respond. You can enroll in the Beta program using your AMP for Endpoints console by navigating to Management &amp;gt; Beta &amp;gt; Enroll. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Feb 2018 07:47:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-can-t-block-the-packered-wannacry/m-p/3431781#M3120</guid>
      <dc:creator>emirolyu</dc:creator>
      <dc:date>2018-02-28T07:47:38Z</dc:date>
    </item>
    <item>
      <title>Re: AMP for endpoint can't block the packered WannaCry.</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-can-t-block-the-packered-wannacry/m-p/3431782#M3121</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your answer. My question was cleared. &lt;IMG src="https://community.cisco.com/legacyfs/online/emoticons/happy.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2018 10:54:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoint-can-t-block-the-packered-wannacry/m-p/3431782#M3121</guid>
      <dc:creator>Tsunoda</dc:creator>
      <dc:date>2018-03-01T10:54:55Z</dc:date>
    </item>
  </channel>
</rss>

