<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco AMP4E  blocking explorer.exe in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/cisco-amp4e-blocking-explorer-exe/m-p/4118544#M5538</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Normally AMP would not block Explorer.exe, due to it is protected by Rail Guards, the fact that AMP is causing this issue points me to think that someone configured an Application blocking and added explorer.exe into it.&lt;/P&gt;
&lt;P&gt;To determine if this is correct, I would go to the Audit Logs (Accounts - Audit Logs), filter by the Policy that is causing the issue and check the update events looking for a change on regards to Application Blocking.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Jul 2020 16:10:33 GMT</pubDate>
    <dc:creator>UMontero</dc:creator>
    <dc:date>2020-07-14T16:10:33Z</dc:date>
    <item>
      <title>Cisco AMP4E  blocking explorer.exe</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp4e-blocking-explorer-exe/m-p/4118252#M5536</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;Cisco AMP4E&amp;nbsp; blocking explorer.exe&amp;nbsp; (windows explorer. exe) and we get black screen.&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to know why it's happened ?&amp;nbsp; Why AMP4E&amp;nbsp; can't&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;get a handle on the process's executable&lt;BR /&gt;On Event details we get this information.&amp;nbsp; (&amp;nbsp;Now i use in audit mode for testing because i get black screen on protect mode.)&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Detected but did not block (Audit mode)&lt;/P&gt;&lt;P&gt;Created by an unknown process. Could&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="warn"&gt;not&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;get a handle on the process's executable.&lt;/P&gt;&lt;HR /&gt;&lt;P&gt;File full path:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="datum long_words"&gt;C:\Windows\explorer.exe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;File SHA-1:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;f7152a8cb963cefdfa65d35a3565c3549b223a26&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;File MD5:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;a77d56422c38c1f8a00d95d2d5b1675e&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;File size:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="datum"&gt;3904296 bytes&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;File age:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="datum"&gt;0 seconds&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;File signed by&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="datum"&gt;Microsoft Windows&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;with certificate serial 330000017469de108b3765a8d7000000000174 from Microsoft Windows Production PCA 2011. Expired 20:23:35, Sat Aug 11 2018 UTC.&lt;/P&gt;&lt;P&gt;File cert MD5:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;0cbcc628b4758f8db5b9048f5136a6c9&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;File cert SHA-1:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;419e77aed546a1a6cf4dc23c1f977542fe289cf7&lt;/SPAN&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 11:30:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp4e-blocking-explorer-exe/m-p/4118252#M5536</guid>
      <dc:creator>sfismayilov</dc:creator>
      <dc:date>2020-07-14T11:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP4E  blocking explorer.exe</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp4e-blocking-explorer-exe/m-p/4118544#M5538</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Normally AMP would not block Explorer.exe, due to it is protected by Rail Guards, the fact that AMP is causing this issue points me to think that someone configured an Application blocking and added explorer.exe into it.&lt;/P&gt;
&lt;P&gt;To determine if this is correct, I would go to the Audit Logs (Accounts - Audit Logs), filter by the Policy that is causing the issue and check the update events looking for a change on regards to Application Blocking.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2020 16:10:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp4e-blocking-explorer-exe/m-p/4118544#M5538</guid>
      <dc:creator>UMontero</dc:creator>
      <dc:date>2020-07-14T16:10:33Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP4E  blocking explorer.exe</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp4e-blocking-explorer-exe/m-p/4118969#M5542</link>
      <description>thanks for your reply.&lt;BR /&gt;we are in deploy phase. İ decided do it afresh and&lt;BR /&gt;i cleaned all block list and another lists. ( there are many people worked on this ).&lt;BR /&gt;i'll track all changes .&lt;BR /&gt;if it will appear again i'll reply</description>
      <pubDate>Wed, 15 Jul 2020 07:48:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp4e-blocking-explorer-exe/m-p/4118969#M5542</guid>
      <dc:creator>sfismayilov</dc:creator>
      <dc:date>2020-07-15T07:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP4E  blocking explorer.exe</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp4e-blocking-explorer-exe/m-p/4119320#M5548</link>
      <description>&lt;P&gt;Got it,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope everything gets resolved, if you encounter any issue, don't hesitate to reply back.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2020 16:37:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp4e-blocking-explorer-exe/m-p/4119320#M5548</guid>
      <dc:creator>UMontero</dc:creator>
      <dc:date>2020-07-15T16:37:09Z</dc:date>
    </item>
  </channel>
</rss>

