<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reverse AMP File Conviction in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/reverse-amp-file-conviction/m-p/4412460#M6153</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You might need to check on the event details to see which engine (such as MAP or Exprev etc.) is blocking the application.&lt;/P&gt;
&lt;P&gt;You can try and make any of the below methods to avoid any conviction for the files:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Scan Exclusions:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Files/Path is not scanned, not hashed - related to any engine doing file scanning.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Process Exclusion:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Anything done by a running process is not scanned.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Application Whitelisting:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;has an impact on two things
&lt;UL&gt;
&lt;LI&gt;Behavioral Engines (e.g. Machine Learning) exclude the hash&lt;/LI&gt;
&lt;LI&gt;The connector does no cloud lookup for the hash&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Engine specific process exclusions:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;The exclusion works for a specific engine&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope the above helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Pratham&lt;/P&gt;</description>
    <pubDate>Thu, 03 Jun 2021 09:06:06 GMT</pubDate>
    <dc:creator>ppreenja</dc:creator>
    <dc:date>2021-06-03T09:06:06Z</dc:date>
    <item>
      <title>Reverse AMP File Conviction</title>
      <link>https://community.cisco.com/t5/endpoint-security/reverse-amp-file-conviction/m-p/4406696#M6144</link>
      <description>&lt;P&gt;Hey People,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Engineering department makes custom applications, and uses GIT sources for applications. Most of the time they're doing things as will, and AMP is convicting these applications as Malicious before I can whitelist the applications. How can i reverse the convictions? Adding the applications to the application allowed list doesn't stop the AMP from blocking them and quarantining the applications.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help would be appreciated, thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 21 May 2021 15:31:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/reverse-amp-file-conviction/m-p/4406696#M6144</guid>
      <dc:creator>ITGuyCSI25</dc:creator>
      <dc:date>2021-05-21T15:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: Reverse AMP File Conviction</title>
      <link>https://community.cisco.com/t5/endpoint-security/reverse-amp-file-conviction/m-p/4412460#M6153</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You might need to check on the event details to see which engine (such as MAP or Exprev etc.) is blocking the application.&lt;/P&gt;
&lt;P&gt;You can try and make any of the below methods to avoid any conviction for the files:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Scan Exclusions:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Files/Path is not scanned, not hashed - related to any engine doing file scanning.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Process Exclusion:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;Anything done by a running process is not scanned.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Application Whitelisting:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;has an impact on two things
&lt;UL&gt;
&lt;LI&gt;Behavioral Engines (e.g. Machine Learning) exclude the hash&lt;/LI&gt;
&lt;LI&gt;The connector does no cloud lookup for the hash&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Engine specific process exclusions:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;The exclusion works for a specific engine&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope the above helps.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Pratham&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 09:06:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/reverse-amp-file-conviction/m-p/4412460#M6153</guid>
      <dc:creator>ppreenja</dc:creator>
      <dc:date>2021-06-03T09:06:06Z</dc:date>
    </item>
  </channel>
</rss>

