<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AMP for Endpoints Simple Custom Detection  quarantine event missing in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-simple-custom-detection-quarantine-event/m-p/4477893#M6416</link>
    <description>&lt;P&gt;According to Cisco Secure Endpoint documentation:&lt;/P&gt;&lt;P&gt;” A Simple Custom Detection list is similar to a blocked list. These are files that you want to detect and quarantine. Not only will an entry in a Simple Custom Detection list quarantine future files, but through Retrospective it will quarantine instances of the file on any endpoints in your organization that the service has already seen it on.” &amp;nbsp;&lt;/P&gt;&lt;P&gt;I have added the hash SHA 256&amp;nbsp;49ebb7feff3bde78611e87adf6cf34b980284e8401c413f409dbb9e3b6d0b642 to&amp;nbsp; Simple Custom Detection list.&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;Cloud IOC: ExecutedMalware.ioc alert is still appearing. File is being detected by&amp;nbsp;&lt;SPAN class="detect_name"&gt;Simple_Custom_Detection and The file was&amp;nbsp;&lt;SPAN class="not_quarantined"&gt;not quarantined&lt;/SPAN&gt;. Quarantine event missing message generates.&amp;nbsp;Benign parent disposition is mentioned. Node&amp;nbsp;belongs to protect policy with conviction modes listed below. Can someone please provide tips on how can I force quarantine?&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Operating System&amp;nbsp;Connector Version&amp;nbsp;Install Date&amp;nbsp;&amp;nbsp;&amp;nbsp;Definition Version&amp;nbsp;Update Server&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Windows 8.1 Enterprise&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;7.4.5.20701&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN class="date"&gt;2021-08-05&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="time"&gt;17:44:36&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="zone"&gt;UTC&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TETRA 64 bit (&lt;STRONG&gt;daily version&lt;/STRONG&gt;: 85783)&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;tetra-defs.amp.cisco.com&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="detect_fname bad long_words"&gt;driverupdate.exe&lt;/SPAN&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="long_words"&gt;DriverUpdate 5.7.0.0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(49ebb7fe…b6d0b642)[PE_Executable] was Executed by&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="detect_fname good long_words"&gt;explorer.exe&lt;/SPAN&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="long_words"&gt;Microsoft® Windows® Operating System 6.3.9600.18460&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(d2faf086…20844fae)[PE_Executable] .&lt;/P&gt;&lt;P&gt;Detected as&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="detect_name"&gt;Simple_Custom_Detection&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;The file was&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="not_quarantined"&gt;not quarantined&lt;/SPAN&gt;. Quarantine event missing.&lt;/P&gt;&lt;P&gt;Benign parent disposition.&lt;/P&gt;&lt;P&gt;File full path:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="datum long_words"&gt;c:\program files\driverupdate\driverupdate.exe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;File SHA-1:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;0a555ca92f6bebb71a511fd413d6a89c3cc8da3b&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;File MD5:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;3e63ff39aa3392d6865543f97bd3613f&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;File size:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="datum"&gt;32502872 bytes&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;File signed by&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="datum"&gt;Slimware Utilities Holdings, Inc.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;with certificate serial 3063b3a740c1cdfdf8bb9e6c331ad7de from VeriSign Class 3 Code Signing 2010 CA. Expired 23:59:59, Mon Jan 7 2019 UTC.&lt;/P&gt;&lt;P&gt;File cert MD5:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;51d9a726e9b891ddd3171aa8cbc0e5c4&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;File cert SHA-1:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;33e24fe66e0117fdd4278699ad423ef2669fd258&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;Parent file SHA-1:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;b642e9fcfac93f219d07bb6d530eb1de9efeb511&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;Parent file MD5:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;ed6b4c95e2a6d67480b9dbb8a8e7d9b4&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;Parent file size:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="datum"&gt;2755504 bytes&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;Parent file signed by&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="datum"&gt;Microsoft Windows&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;with certificate serial 33000000bce120fdd27cc8ee930000000000bc from Microsoft Windows Production PCA 2011. Expired 17:15:28, Fri Nov 18 2016 UTC.&lt;/P&gt;&lt;P&gt;Parent file cert MD5:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;747a40b8593fdb7977bf60ba6f06778b&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;Parent file cert SHA-1:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;e85459b23c232db3cb94c7a56d47678f58e8e51e&lt;/SPAN&gt;.&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="amp123.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/132877iEE449794220796F9/image-size/large?v=v2&amp;amp;px=999" role="button" title="amp123.PNG" alt="amp123.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AMP2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/132875i200D167A147E668D/image-size/large?v=v2&amp;amp;px=999" role="button" title="AMP2.PNG" alt="AMP2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="conviction modes.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/132879i9139B399759884AB/image-size/large?v=v2&amp;amp;px=999" role="button" title="conviction modes.PNG" alt="conviction modes.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
    <pubDate>Thu, 30 Sep 2021 18:19:51 GMT</pubDate>
    <dc:creator>Paladin</dc:creator>
    <dc:date>2021-09-30T18:19:51Z</dc:date>
    <item>
      <title>AMP for Endpoints Simple Custom Detection  quarantine event missing</title>
      <link>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-simple-custom-detection-quarantine-event/m-p/4477893#M6416</link>
      <description>&lt;P&gt;According to Cisco Secure Endpoint documentation:&lt;/P&gt;&lt;P&gt;” A Simple Custom Detection list is similar to a blocked list. These are files that you want to detect and quarantine. Not only will an entry in a Simple Custom Detection list quarantine future files, but through Retrospective it will quarantine instances of the file on any endpoints in your organization that the service has already seen it on.” &amp;nbsp;&lt;/P&gt;&lt;P&gt;I have added the hash SHA 256&amp;nbsp;49ebb7feff3bde78611e87adf6cf34b980284e8401c413f409dbb9e3b6d0b642 to&amp;nbsp; Simple Custom Detection list.&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;Cloud IOC: ExecutedMalware.ioc alert is still appearing. File is being detected by&amp;nbsp;&lt;SPAN class="detect_name"&gt;Simple_Custom_Detection and The file was&amp;nbsp;&lt;SPAN class="not_quarantined"&gt;not quarantined&lt;/SPAN&gt;. Quarantine event missing message generates.&amp;nbsp;Benign parent disposition is mentioned. Node&amp;nbsp;belongs to protect policy with conviction modes listed below. Can someone please provide tips on how can I force quarantine?&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Operating System&amp;nbsp;Connector Version&amp;nbsp;Install Date&amp;nbsp;&amp;nbsp;&amp;nbsp;Definition Version&amp;nbsp;Update Server&lt;/P&gt;&lt;TABLE&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;Windows 8.1 Enterprise&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;7.4.5.20701&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&lt;SPAN class="date"&gt;2021-08-05&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="time"&gt;17:44:36&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="zone"&gt;UTC&lt;/SPAN&gt;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;TETRA 64 bit (&lt;STRONG&gt;daily version&lt;/STRONG&gt;: 85783)&lt;/TD&gt;&lt;TD&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD&gt;tetra-defs.amp.cisco.com&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="detect_fname bad long_words"&gt;driverupdate.exe&lt;/SPAN&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="long_words"&gt;DriverUpdate 5.7.0.0&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(49ebb7fe…b6d0b642)[PE_Executable] was Executed by&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="detect_fname good long_words"&gt;explorer.exe&lt;/SPAN&gt;,&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="long_words"&gt;Microsoft® Windows® Operating System 6.3.9600.18460&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(d2faf086…20844fae)[PE_Executable] .&lt;/P&gt;&lt;P&gt;Detected as&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="detect_name"&gt;Simple_Custom_Detection&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;The file was&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="not_quarantined"&gt;not quarantined&lt;/SPAN&gt;. Quarantine event missing.&lt;/P&gt;&lt;P&gt;Benign parent disposition.&lt;/P&gt;&lt;P&gt;File full path:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="datum long_words"&gt;c:\program files\driverupdate\driverupdate.exe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;File SHA-1:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;0a555ca92f6bebb71a511fd413d6a89c3cc8da3b&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;File MD5:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;3e63ff39aa3392d6865543f97bd3613f&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;File size:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="datum"&gt;32502872 bytes&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;File signed by&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="datum"&gt;Slimware Utilities Holdings, Inc.&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;with certificate serial 3063b3a740c1cdfdf8bb9e6c331ad7de from VeriSign Class 3 Code Signing 2010 CA. Expired 23:59:59, Mon Jan 7 2019 UTC.&lt;/P&gt;&lt;P&gt;File cert MD5:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;51d9a726e9b891ddd3171aa8cbc0e5c4&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;File cert SHA-1:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;33e24fe66e0117fdd4278699ad423ef2669fd258&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;Parent file SHA-1:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;b642e9fcfac93f219d07bb6d530eb1de9efeb511&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;Parent file MD5:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;ed6b4c95e2a6d67480b9dbb8a8e7d9b4&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;Parent file size:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="datum"&gt;2755504 bytes&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;Parent file signed by&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="datum"&gt;Microsoft Windows&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;with certificate serial 33000000bce120fdd27cc8ee930000000000bc from Microsoft Windows Production PCA 2011. Expired 17:15:28, Fri Nov 18 2016 UTC.&lt;/P&gt;&lt;P&gt;Parent file cert MD5:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;747a40b8593fdb7977bf60ba6f06778b&lt;/SPAN&gt;.&lt;/P&gt;&lt;P&gt;Parent file cert SHA-1:&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="det_smaller datum"&gt;e85459b23c232db3cb94c7a56d47678f58e8e51e&lt;/SPAN&gt;.&lt;/P&gt;&lt;DIV class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="amp123.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/132877iEE449794220796F9/image-size/large?v=v2&amp;amp;px=999" role="button" title="amp123.PNG" alt="amp123.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AMP2.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/132875i200D167A147E668D/image-size/large?v=v2&amp;amp;px=999" role="button" title="AMP2.PNG" alt="AMP2.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="conviction modes.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/132879i9139B399759884AB/image-size/large?v=v2&amp;amp;px=999" role="button" title="conviction modes.PNG" alt="conviction modes.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 30 Sep 2021 18:19:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amp-for-endpoints-simple-custom-detection-quarantine-event/m-p/4477893#M6416</guid>
      <dc:creator>Paladin</dc:creator>
      <dc:date>2021-09-30T18:19:51Z</dc:date>
    </item>
  </channel>
</rss>

