<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Does Cisco Amp scan for rootkits? in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/does-cisco-amp-scan-for-rootkits/m-p/4518814#M6549</link>
    <description>&lt;P&gt;My organization has Cisco Amp for endpoint protection. The question we have is whether Amp scans for rootkits? We are also seeing a very high number of executable files show up as potential threats. Does Amp flag all ".exe" files as threats? Excel spreadsheets and system files are also showing up as potential threats. Does Amp flag all .xlsx files and system files as potential threats as well?&lt;/P&gt;</description>
    <pubDate>Tue, 14 Dec 2021 17:25:03 GMT</pubDate>
    <dc:creator>kristina.robinson</dc:creator>
    <dc:date>2021-12-14T17:25:03Z</dc:date>
    <item>
      <title>Does Cisco Amp scan for rootkits?</title>
      <link>https://community.cisco.com/t5/endpoint-security/does-cisco-amp-scan-for-rootkits/m-p/4518814#M6549</link>
      <description>&lt;P&gt;My organization has Cisco Amp for endpoint protection. The question we have is whether Amp scans for rootkits? We are also seeing a very high number of executable files show up as potential threats. Does Amp flag all ".exe" files as threats? Excel spreadsheets and system files are also showing up as potential threats. Does Amp flag all .xlsx files and system files as potential threats as well?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 17:25:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/does-cisco-amp-scan-for-rootkits/m-p/4518814#M6549</guid>
      <dc:creator>kristina.robinson</dc:creator>
      <dc:date>2021-12-14T17:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco Amp scan for rootkits?</title>
      <link>https://community.cisco.com/t5/endpoint-security/does-cisco-amp-scan-for-rootkits/m-p/4518849#M6550</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1288893"&gt;@kristina.robinson&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;so let me try to answer your questions step-by-step&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;Rootkit Scan:&lt;/STRONG&gt; Yes we do. There is an own OnDemand Scan available on the endpoint. Thought this has been already fixed in the console.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Potential Threats:&lt;/STRONG&gt; What type of Events are shown exactly? And no, Secure Endpoint does not flag all .exe files as threats. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;All Engines also include "guardrails" to prevent False/Positves.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;File Scanning:&lt;/STRONG&gt; The graphics below shows how Secure Endpoint protects against threats. For File Scanning the endpoint does several steps to detect malicious files. The Device Trajectory shows more information which engines processed a file and which engine triggered a detection. There are some aspects which have an impact on the detection. This can be the cache or configured exclusions.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="TME-SecureEndpoint-Engines Behavioral v2.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/139484i453057C5AA4F0C67/image-size/large?v=v2&amp;amp;px=999" role="button" title="TME-SecureEndpoint-Engines Behavioral v2.png" alt="TME-SecureEndpoint-Engines Behavioral v2.png" /&gt;&lt;/span&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;So finally, Secure Endpoint does not mark executable code or office documents as threats. Especially system files, as we use the guardrails to prevent the system from false/positives. I would suggest to open a TAC case so someone takes a deeper look into your environment. Based on your description I cannot provide any reliable statement what is going on on your endpoint.&lt;/P&gt;
&lt;P&gt;Greetings,&lt;BR /&gt;Thorsten&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 18:15:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/does-cisco-amp-scan-for-rootkits/m-p/4518849#M6550</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2021-12-14T18:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco Amp scan for rootkits?</title>
      <link>https://community.cisco.com/t5/endpoint-security/does-cisco-amp-scan-for-rootkits/m-p/4518900#M6552</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;So are you saying that when I run full scans in Amp, it is automatically checking for rootkits as well or is there a separate scan to run for rootkits?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Dec 2021 19:18:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/does-cisco-amp-scan-for-rootkits/m-p/4518900#M6552</guid>
      <dc:creator>kristina.robinson</dc:creator>
      <dc:date>2021-12-14T19:18:16Z</dc:date>
    </item>
    <item>
      <title>Re: Does Cisco Amp scan for rootkits?</title>
      <link>https://community.cisco.com/t5/endpoint-security/does-cisco-amp-scan-for-rootkits/m-p/4519164#M6553</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1288893"&gt;@kristina.robinson&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;looks like there is an issue in the Console UI. So you can start a Rootkit scan on the endpoint, but not remotely from the console. You may check with TAC to get this solved.&lt;BR /&gt;Greetings,&lt;BR /&gt;Thorsten&lt;/P&gt;</description>
      <pubDate>Wed, 15 Dec 2021 08:18:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/does-cisco-amp-scan-for-rootkits/m-p/4519164#M6553</guid>
      <dc:creator>Troja007</dc:creator>
      <dc:date>2021-12-15T08:18:22Z</dc:date>
    </item>
  </channel>
</rss>

