<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Whitelist file that has a dynamic SHA name in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/whitelist-file-that-has-a-dynamic-sha-name/m-p/4466106#M6390</link>
    <description>&lt;P&gt;It was detected by Tetra. I opened a ticket but it was asking for the SHA name, which is dynamic. So we'll see what happens.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Sep 2021 12:45:14 GMT</pubDate>
    <dc:creator>itguy1024</dc:creator>
    <dc:date>2021-09-14T12:45:14Z</dc:date>
    <item>
      <title>Whitelist file that has a dynamic SHA name</title>
      <link>https://community.cisco.com/t5/endpoint-security/whitelist-file-that-has-a-dynamic-sha-name/m-p/4465106#M6386</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a .lnk file being pushed out by GPO that AMP has been blocking. AMP has been flagging it as Heur.BZC.ONG.Boxter.331.47822C71 and quarantining it.&lt;BR /&gt;I have been whitelisting it but noticed that in AMP the .lnk file has a different SHA name each time it gets quarantined. I'm guessing that's why it keeps getting blocked.&lt;BR /&gt;I did select the actual file .lnk file name and add to whitelist but assuming it's the same issue with the SHA names.&lt;BR /&gt;&lt;BR /&gt;Is there any other way to add a file to the whitelist that doesn't look at the SHA names?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2021 14:38:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/whitelist-file-that-has-a-dynamic-sha-name/m-p/4465106#M6386</guid>
      <dc:creator>itguy1024</dc:creator>
      <dc:date>2021-09-13T14:38:53Z</dc:date>
    </item>
    <item>
      <title>Re: Whitelist file that has a dynamic SHA name</title>
      <link>https://community.cisco.com/t5/endpoint-security/whitelist-file-that-has-a-dynamic-sha-name/m-p/4465999#M6389</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Based on the detection name, files in question are detected by TETRA engine (signature based engine, like traditional AVs) - to confirm that, you can check details in Device Trajectory - it should display which engine was involved. Please refer to example from my lab:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-09-14 at 13.10.41.png" style="width: 339px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/130830i0597C7A7B0F8B71F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-09-14 at 13.10.41.png" alt="Screenshot 2021-09-14 at 13.10.41.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-family: inherit;"&gt;The best way to address that -&amp;gt; open ticket with Talos and provide sample + engine that detected file under&amp;nbsp;&lt;A href="https://talosintelligence.com/tickets" target="_blank"&gt;https://talosintelligence.com/tickets&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Once they will review the file and confirm it is False Positive, all files with the same file properties should not be detected by Secure Endpoint anymore.&lt;/P&gt;
&lt;P&gt;-Wojciech&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 11:17:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/whitelist-file-that-has-a-dynamic-sha-name/m-p/4465999#M6389</guid>
      <dc:creator>Wojciech Cecot</dc:creator>
      <dc:date>2021-09-14T11:17:24Z</dc:date>
    </item>
    <item>
      <title>Re: Whitelist file that has a dynamic SHA name</title>
      <link>https://community.cisco.com/t5/endpoint-security/whitelist-file-that-has-a-dynamic-sha-name/m-p/4466106#M6390</link>
      <description>&lt;P&gt;It was detected by Tetra. I opened a ticket but it was asking for the SHA name, which is dynamic. So we'll see what happens.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2021 12:45:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/whitelist-file-that-has-a-dynamic-sha-name/m-p/4466106#M6390</guid>
      <dc:creator>itguy1024</dc:creator>
      <dc:date>2021-09-14T12:45:14Z</dc:date>
    </item>
    <item>
      <title>Re: Whitelist file that has a dynamic SHA name</title>
      <link>https://community.cisco.com/t5/endpoint-security/whitelist-file-that-has-a-dynamic-sha-name/m-p/4467734#M6399</link>
      <description>&lt;P&gt;Update: Talos closed my case and marked it as no change. They stated that AMP is not blocking the file and I should open a TAC case. This is odd because I can watch AMP quarantine the file in real time when I try to deploy it.&lt;BR /&gt;I guess I'll see what TAC says.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 14:35:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/whitelist-file-that-has-a-dynamic-sha-name/m-p/4467734#M6399</guid>
      <dc:creator>itguy1024</dc:creator>
      <dc:date>2021-09-16T14:35:15Z</dc:date>
    </item>
  </channel>
</rss>

