<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: exclude/whiteliste certain powershell commands in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4258960#M5878</link>
    <description>&lt;P&gt;Can you elaborate? Where/how can we exclude by IOC?&lt;/P&gt;</description>
    <pubDate>Tue, 15 Dec 2020 18:41:16 GMT</pubDate>
    <dc:creator>Shinku</dc:creator>
    <dc:date>2020-12-15T18:41:16Z</dc:date>
    <item>
      <title>exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3939116#M3257</link>
      <description>&lt;P&gt;Admins being admins like to use powershell to solve certain task. To do this they will often run a powershell file downloaded from a server, i.e:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;C:\windows\system32\WindowsPowerShell\v1.0\powershell.exe -NoProfile -ExecutionPolicy Bypass -Command iex ((New-Object System.Net.WebClient).DownloadString('&lt;A href="https://example.com/script.ps1" target="_blank"&gt;https://example.com/script.ps1&lt;/A&gt;'))&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This being an obvious red flag triggers AMP, but gives a lot of false positives in this case.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is there any way to exclude/whitelist something like this? Like the full command with arguments, the server from which it downloads??&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thomas&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 05:11:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3939116#M3257</guid>
      <dc:creator>thomas.methlie</dc:creator>
      <dc:date>2020-02-21T05:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3939163#M3260</link>
      <description>&lt;P&gt;Are you looking to exclude this AMP for end point, here is the exclustiondocument to exclude certain extension as per the requirement,ent.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/213681-best-practices-for-amp-for-endpoint-excl.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/213681-best-practices-for-amp-for-endpoint-excl.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2019 10:10:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3939163#M3260</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-10-11T10:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3939201#M3262</link>
      <description>&lt;P&gt;thanks but that guide doesn´t provide any info on my problem. To be more precise, I don´t want to exclude powershell process or ps script files on a general basis&lt;/P&gt;</description>
      <pubDate>Fri, 11 Oct 2019 11:42:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3939201#M3262</guid>
      <dc:creator>thomas.methlie</dc:creator>
      <dc:date>2019-10-11T11:42:30Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3941601#M3264</link>
      <description>&lt;P&gt;Hello Thomas,&lt;/P&gt;
&lt;P&gt;sorry to say, but, as explained in the documentation this is the way we can handle exclusions today. The best way is to report this missing feature to your Cisco Representative to open a Feature Request for this.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to be sure: You are getting a lot of IOCs?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings,&lt;/P&gt;
&lt;P&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 11:43:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3941601#M3264</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2019-10-16T11:43:13Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3941604#M3266</link>
      <description>&lt;P&gt;Opened a Feature Request for you.&lt;/P&gt;
&lt;P&gt;Greetings,&lt;/P&gt;
&lt;P&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 11:47:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3941604#M3266</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2019-10-16T11:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3941666#M3268</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;yeah this is one of our largest sources of false positive alerts and spend quite some time cleaning up the dashboard. Could of course mute the events, but I don´t feel comfortable muting too much stuff.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for opening a Feature Request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 13:32:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3941666#M3268</guid>
      <dc:creator>thomas.methlie</dc:creator>
      <dc:date>2019-10-16T13:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3942469#M3269</link>
      <description>&lt;P&gt;So,&lt;/P&gt;
&lt;P&gt;what would help? Defining an exclusion with several parameters?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Including:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Path of the Process, Process name&lt;/LI&gt;
&lt;LI&gt;Hash and Signer&lt;/LI&gt;
&lt;LI&gt;Source where the file is downloaded from&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;Looks easy, but is much more development effort. The questions is, where to enforce.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Endpoint: We have to define how big the time window is the endpoint can monitor AND what the performance/resource impact on the endpoint is.&lt;/LI&gt;
&lt;LI&gt;Backend: Changing the whole logic. This must be done for every customer, because exclusions will be different.
&lt;UL&gt;
&lt;LI&gt;We also need some kind of "plausibility check" to avoid impacts in the backend based on wrong defined exclusions.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;But finally, something which should be included in the product.&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 11:54:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3942469#M3269</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2019-10-17T11:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3945066#M3270</link>
      <description>&lt;P&gt;Yes, the three parameters you mention is what I was initially thinking of.&lt;/P&gt;&lt;P&gt;If there is a need to assist in testing this, I would be happy to help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Thomas&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 07:36:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3945066#M3270</guid>
      <dc:creator>thomas.methlie</dc:creator>
      <dc:date>2019-10-22T07:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3946164#M3273</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/888392"&gt;@thomas.methlie&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;the only way today is, getting in contact with your Cisco Representative to open a Feature Request.&lt;/P&gt;
&lt;P&gt;Greetings,&lt;/P&gt;
&lt;P&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 09:45:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3946164#M3273</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2019-10-23T09:45:05Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3958904#M3274</link>
      <description>&lt;P&gt;We're waiting with bated breath for this feature to come out as we have the same problem. We use powershell to deploy all our stuff and it triggers Cisco AMP on a weekly basis with false positives. It's causing alert fatigue for our analysts but we don't want to exclude ALL powershell.exe as some of them might in fact be malicious. Please please please give us this new feature that allows exclusions on specific powershell scripts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 14 Nov 2019 20:43:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3958904#M3274</guid>
      <dc:creator>POAL</dc:creator>
      <dc:date>2019-11-14T20:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3958958#M3276</link>
      <description>There is one option at the moment to exclude particular IOC by the TAC case.&lt;BR /&gt;&lt;BR /&gt;Radek&lt;BR /&gt;</description>
      <pubDate>Thu, 14 Nov 2019 21:28:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/3958958#M3276</guid>
      <dc:creator>rolszowy</dc:creator>
      <dc:date>2019-11-14T21:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4258960#M5878</link>
      <description>&lt;P&gt;Can you elaborate? Where/how can we exclude by IOC?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Dec 2020 18:41:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4258960#M5878</guid>
      <dc:creator>Shinku</dc:creator>
      <dc:date>2020-12-15T18:41:16Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4318801#M6075</link>
      <description>&lt;P&gt;What is the feature request number?&amp;nbsp; Roadmap timing for this?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Apr 2021 17:39:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4318801#M6075</guid>
      <dc:creator>gmcclintick1</dc:creator>
      <dc:date>2021-04-05T17:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4319164#M6076</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;this Feature Request is an internal one, and not public viewable. You may get in touch with your Cisco representative to get more insights into upcoming features in the product.&lt;/P&gt;
&lt;P&gt;As the roadmap can always get updated, we do not publish this information in the community.&lt;/P&gt;
&lt;P&gt;Greetings,&lt;/P&gt;
&lt;P&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Tue, 06 Apr 2021 09:22:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4319164#M6076</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2021-04-06T09:22:11Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4572580#M6761</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;&lt;BR /&gt;is there any new information on this feature request?&amp;nbsp;&lt;BR /&gt;Has this already been implemented?&lt;BR /&gt;&lt;BR /&gt;Thanks for response&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 12:49:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4572580#M6761</guid>
      <dc:creator>SebastianF</dc:creator>
      <dc:date>2022-03-17T12:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4701880#M7124</link>
      <description>&lt;P&gt;Ping on this topic. I'm also looking for a way to use command parameter content to form an exclusion. In my case the offending command is:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="python"&gt;C:\WINDOWS\system32\cmd.exe /d /c C:\Program Files (x86)\ThousandEyes\Endpoint Agent\te-chromehelper.exe chrome-extension://obdencanbejmhpbikpcgkdflkffifoof/ --parent-window=0 &amp;lt; \\.\pipe\LOCAL\edge.nativeMessaging.in.43b0764b69528ed5 &amp;gt; \\.\pipe\LOCAL\edge.nativeMessaging.out.43b0764b69528ed5&lt;/LI-CODE&gt;&lt;P&gt;&lt;SPAN class=""&gt;I'd love to be able to wildcard and use the "ThousandEyes" portion of the command parameter for the exclusion.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 12:08:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4701880#M7124</guid>
      <dc:creator>MichaelErana</dc:creator>
      <dc:date>2022-10-12T12:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4701903#M7125</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/893678"&gt;@MichaelErana&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;feature is under development. You may ping your Cisco representative for more details. We do not share Roadmap information here in the community.&amp;nbsp;&lt;BR /&gt;Thanks and Greetings,&lt;BR /&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 12:30:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4701903#M7125</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2022-10-12T12:30:18Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4704869#M7133</link>
      <description>&lt;P&gt;I saw the feature request was going in in 2019,&amp;nbsp; any update on it?&lt;/P&gt;</description>
      <pubDate>Tue, 18 Oct 2022 12:52:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4704869#M7133</guid>
      <dc:creator>Davedog</dc:creator>
      <dc:date>2022-10-18T12:52:12Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4704888#M7137</link>
      <description>They know its an issue, it was talked about at a CAB/Forum I was at recently.  I feel like its "coming soon", but honestly can't remember if there was a date or version mentioned...&lt;BR /&gt;&lt;BR /&gt;But they know it creates false positives and know that's an issue.&lt;BR /&gt;&lt;BR /&gt;Ken&lt;BR /&gt;</description>
      <pubDate>Tue, 18 Oct 2022 13:25:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4704888#M7137</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2022-10-18T13:25:38Z</dc:date>
    </item>
    <item>
      <title>Re: exclude/whiteliste certain powershell commands</title>
      <link>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4930213#M7836</link>
      <description>&lt;P&gt;Hey, we don't have a cisco rep but this feature request has been open since 2019, any news on when it's actually going to be released? I can make these exclusions in every other product apart from AMP and it's causing a lot of noise. Does it really take almost 4 years to develop this feature?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Sep 2023 09:55:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/exclude-whiteliste-certain-powershell-commands/m-p/4930213#M7836</guid>
      <dc:creator>sdawson14</dc:creator>
      <dc:date>2023-09-27T09:55:12Z</dc:date>
    </item>
  </channel>
</rss>

