<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AMP 4 Endpoint questions in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/amp-4-endpoint-questions/m-p/4302121#M6025</link>
    <description>1. No, user can reboot... and after 7.x, reboot requirements mostly go away.&lt;BR /&gt;&lt;BR /&gt;2. Talosintelligence.com... thou&lt;BR /&gt;&lt;BR /&gt;3. Yes, under Outbreak Controls/Automated Actions. These also show up as Orchestrations in SecureX/Orchestrations&lt;BR /&gt;&lt;BR /&gt;4. Yes, under Outbreak Controls/Automated Actions. These also show up as Orchestrations in SecureX/Orchestrations&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
    <pubDate>Fri, 05 Mar 2021 15:45:03 GMT</pubDate>
    <dc:creator>Ken Stieers</dc:creator>
    <dc:date>2021-03-05T15:45:03Z</dc:date>
    <item>
      <title>AMP 4 Endpoint questions</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-4-endpoint-questions/m-p/4302031#M6024</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would like to ask some questions about the operation of AMP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. When upgrading an agent, the reboot after needs to be done with privileged account?&lt;/P&gt;&lt;P&gt;2. Is there a site that hosts IOC xml files?&lt;/P&gt;&lt;P&gt;3. Is there a way for AMP to automatically upload files to threatgrid?&lt;/P&gt;&lt;P&gt;4. The endpoint isolation could be done automatically?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Konstantinos&lt;/P&gt;</description>
      <pubDate>Fri, 05 Mar 2021 12:52:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-4-endpoint-questions/m-p/4302031#M6024</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-03-05T12:52:50Z</dc:date>
    </item>
    <item>
      <title>Re: AMP 4 Endpoint questions</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-4-endpoint-questions/m-p/4302121#M6025</link>
      <description>1. No, user can reboot... and after 7.x, reboot requirements mostly go away.&lt;BR /&gt;&lt;BR /&gt;2. Talosintelligence.com... thou&lt;BR /&gt;&lt;BR /&gt;3. Yes, under Outbreak Controls/Automated Actions. These also show up as Orchestrations in SecureX/Orchestrations&lt;BR /&gt;&lt;BR /&gt;4. Yes, under Outbreak Controls/Automated Actions. These also show up as Orchestrations in SecureX/Orchestrations&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 05 Mar 2021 15:45:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-4-endpoint-questions/m-p/4302121#M6025</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2021-03-05T15:45:03Z</dc:date>
    </item>
    <item>
      <title>Re: AMP 4 Endpoint questions</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-4-endpoint-questions/m-p/4302942#M6026</link>
      <description>&lt;P&gt;Good morning!!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for the answers!&lt;/P&gt;&lt;P&gt;1. So if it does not update with normal user there is a problem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Where exactly? I cannot find an .xml file for IOCs&lt;/P&gt;&lt;P&gt;3. Great! Found it!&lt;/P&gt;&lt;P&gt;4. Found it! I can see that the criteria is only the severity. Is there a way to choose sth else?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Konstantinos&lt;/P&gt;</description>
      <pubDate>Mon, 08 Mar 2021 06:26:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-4-endpoint-questions/m-p/4302942#M6026</guid>
      <dc:creator>kostasthedelegate</dc:creator>
      <dc:date>2021-03-08T06:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: AMP 4 Endpoint questions</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-4-endpoint-questions/m-p/4302971#M6027</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/864895"&gt;@kostasthedelegate&lt;/a&gt;,&lt;BR /&gt;some infos inoline..&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for the answers!&lt;/P&gt;
&lt;P&gt;1. So if it does not update with normal user there is a problem.&amp;nbsp;&lt;BR /&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; The endpoint upgrade is completely independent from the logged on user... you can also do an upgrade if no user is logged on.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;2. Where exactly? I cannot find an .xml file for IOCs&lt;BR /&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; Hello, there is not a List of .xml files. If there is a e.g. blog post (&lt;A href="https://blog.talosintelligence.com/2018/02/olympic-destroyer.html" target="_self"&gt;example&lt;/A&gt;), it includes observavles or IOC information, you can use the SecureX Browser add-on to directly add them to a casebook and to investigate your environment.&amp;nbsp;&lt;BR /&gt;The intelligence in the Backend for Cloud IOC generation is constantly updated by Cisco. The IOC information, e.g. on Talos Website, can be used to do additional Threat Hunt and investigations.&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="font-family: inherit;"&gt;3. Great! Found it!&lt;BR /&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; great&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;4. Found it! I can see that the criteria is only the severity. Is there a way to choose sth else?&lt;BR /&gt;&lt;STRONG&gt;A:&lt;/STRONG&gt; automated actions inside Secure Endpoint Console are always triggered by an IOC. In addition, you can use the API to trigger them from external sources. OR, you can build your personal Orchestration Workflows (SecureX) and trigger them. Orchestration Workflows can also be triggered from external.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetins,&lt;BR /&gt;Thorsten&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;.. did some smaller updates to remove typos.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Mar 2021 06:30:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-4-endpoint-questions/m-p/4302971#M6027</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2021-03-11T06:30:28Z</dc:date>
    </item>
  </channel>
</rss>

