<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remove detected items in AMP in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/remove-detected-items-in-amp/m-p/3844075#M3285</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;Wojciech,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have the exact same output. Thank you for your response!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would like to ask you something more.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have noticed that AMP raises events the exact same time, for the same file(malware,trojan,etc...) with 2 different statuses (Quarantine:Failed , Quarantine:Successful) for the same user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Below an example&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/35368i6C495162EBD7AFC4/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How should i treat such events? Have it quarantined it or not ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;NOTE: I have also noticed that AMP may raise many Quarantine:Failed events for a file and one(or none)&amp;nbsp;Quarantine:Successful&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giannis&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 24 Apr 2019 12:03:02 GMT</pubDate>
    <dc:creator>anousakisioannis</dc:creator>
    <dc:date>2019-04-24T12:03:02Z</dc:date>
    <item>
      <title>Remove detected items in AMP</title>
      <link>https://community.cisco.com/t5/endpoint-security/remove-detected-items-in-amp/m-p/3843950#M3280</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I ran a full scan in AMP for a client and it returned the below message:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Scanned 244494 files, 109 processes, 37615 paths. Found 2 malicious items.&lt;/P&gt;&lt;P&gt;When i expand the event, i cannot see these malicious items.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After the "Scan Started" event it has quarantined 2 malwares. Are, these 2 events, the malicious items that mention in the summary?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:08:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/remove-detected-items-in-amp/m-p/3843950#M3280</guid>
      <dc:creator>anousakisioannis</dc:creator>
      <dc:date>2020-02-21T05:08:48Z</dc:date>
    </item>
    <item>
      <title>Re: Remove detected items in AMP</title>
      <link>https://community.cisco.com/t5/endpoint-security/remove-detected-items-in-amp/m-p/3844055#M3283</link>
      <description>&lt;P&gt;Hello Sir,&lt;/P&gt;
&lt;P&gt;Yes, most probably those will be the files from the full scan. Let me share example from the lab:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2019-04-24 at 13.28.52.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/35364i6932EA9C80939675/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2019-04-24 at 13.28.52.png" alt="Screenshot 2019-04-24 at 13.28.52.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;There is also another way, you can look for specific file in Device Trajectory (from the Events section), for example:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2019-04-24 at 13.32.47.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/35365i820E224A15726DA8/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2019-04-24 at 13.32.47.png" alt="Screenshot 2019-04-24 at 13.32.47.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;It will show up details with information: "Detected (...) during a full scan.":&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2019-04-24 at 13.34.13.png" style="width: 395px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/35366i68DB3EB2236F5E7A/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2019-04-24 at 13.34.13.png" alt="Screenshot 2019-04-24 at 13.34.13.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Hope that helps,&lt;/P&gt;
&lt;P&gt;Wojciech&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 11:37:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/remove-detected-items-in-amp/m-p/3844055#M3283</guid>
      <dc:creator>Wojciech Cecot</dc:creator>
      <dc:date>2019-04-24T11:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: Remove detected items in AMP</title>
      <link>https://community.cisco.com/t5/endpoint-security/remove-detected-items-in-amp/m-p/3844075#M3285</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;Wojciech,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have the exact same output. Thank you for your response!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would like to ask you something more.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have noticed that AMP raises events the exact same time, for the same file(malware,trojan,etc...) with 2 different statuses (Quarantine:Failed , Quarantine:Successful) for the same user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Below an example&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/35368i6C495162EBD7AFC4/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How should i treat such events? Have it quarantined it or not ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;NOTE: I have also noticed that AMP may raise many Quarantine:Failed events for a file and one(or none)&amp;nbsp;Quarantine:Successful&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giannis&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 12:03:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/remove-detected-items-in-amp/m-p/3844075#M3285</guid>
      <dc:creator>anousakisioannis</dc:creator>
      <dc:date>2019-04-24T12:03:02Z</dc:date>
    </item>
    <item>
      <title>Re: Remove detected items in AMP</title>
      <link>https://community.cisco.com/t5/endpoint-security/remove-detected-items-in-amp/m-p/3844079#M3286</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;SPAN&gt;Wojciech,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have the exact same output. Thank you for your response!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I would like to ask you something more.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have noticed that AMP raises events the exact same time, for the same file(malware,trojan,etc...) with 2 different statuses (Quarantine:Failed , Quarantine:Successful) for the same user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Below an example&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Capture.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/35369iA44BF7E90A0906B8/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;How should i treat such events? Have it quarantined it or not ?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;NOTE: I have also noticed that AMP may raise many Quarantine:Failed events for a file and one(or none)&amp;nbsp;Quarantine:Successful&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giannis&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 12:04:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/remove-detected-items-in-amp/m-p/3844079#M3286</guid>
      <dc:creator>anousakisioannis</dc:creator>
      <dc:date>2019-04-24T12:04:41Z</dc:date>
    </item>
    <item>
      <title>Re: Remove detected items in AMP</title>
      <link>https://community.cisco.com/t5/endpoint-security/remove-detected-items-in-amp/m-p/3844094#M3287</link>
      <description>&lt;P&gt;Hello Giannis,&lt;/P&gt;
&lt;P&gt;You are welcome. Regarding your another query, that is quite common. The reason AMP could not quarantine may be: &lt;BR /&gt;- it could be that another process (may be another AV) had already moved the file from that location,&lt;BR /&gt;- it could be permission issue that another process or AV had stopped AMP from getting handle on that file,&lt;BR /&gt;- sometimes there is follow up quarantine successful event (your case) after quarantine failed, that means that some other process had handle on that file before.&lt;/P&gt;
&lt;P&gt;The quarantine fail event just happened to come above the successful (most probably because of sorting while that is the same timestamp). However, the successful quarantine would indicate that the file was quarantined properly.&lt;/P&gt;
&lt;P&gt;--Wojciech&lt;/P&gt;</description>
      <pubDate>Wed, 24 Apr 2019 12:23:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/remove-detected-items-in-amp/m-p/3844094#M3287</guid>
      <dc:creator>Wojciech Cecot</dc:creator>
      <dc:date>2019-04-24T12:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: Remove detected items in AMP</title>
      <link>https://community.cisco.com/t5/endpoint-security/remove-detected-items-in-amp/m-p/3858185#M3288</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Wojciech,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sorry for reopening this case but i have a question that matches in this conversation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I tried to manually delete the quarantines files from&amp;nbsp;C:\Program Files\Cisco\AMP\Quarantine but i couldn't due to permissions access and i was logged in as admin.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Do you know why is this happening? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is there any way to manually delete the quarantined files or from the management console?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giannis&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 09:59:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/remove-detected-items-in-amp/m-p/3858185#M3288</guid>
      <dc:creator>anousakisioannis</dc:creator>
      <dc:date>2019-05-17T09:59:50Z</dc:date>
    </item>
    <item>
      <title>Re: Remove detected items in AMP</title>
      <link>https://community.cisco.com/t5/endpoint-security/remove-detected-items-in-amp/m-p/3858240#M3289</link>
      <description>&lt;P&gt;Giannis,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You'll need to stop the service before you can delete the files.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Matt&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2019 11:40:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/remove-detected-items-in-amp/m-p/3858240#M3289</guid>
      <dc:creator>Matthew Franks</dc:creator>
      <dc:date>2019-05-17T11:40:40Z</dc:date>
    </item>
    <item>
      <title>Re: Remove detected items in AMP</title>
      <link>https://community.cisco.com/t5/endpoint-security/remove-detected-items-in-amp/m-p/4107775#M5476</link>
      <description>@Wojcieh Cecot : So how can we find out which quarantine failed is really failed??? Since it may include the entries which are already quarantined.</description>
      <pubDate>Tue, 23 Jun 2020 06:47:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/remove-detected-items-in-amp/m-p/4107775#M5476</guid>
      <dc:creator>VineeshKV89423</dc:creator>
      <dc:date>2020-06-23T06:47:55Z</dc:date>
    </item>
  </channel>
</rss>

