<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Allowed Application Still Being Quarantined in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/allowed-application-still-being-quarantined/m-p/4568964#M6753</link>
    <description>&lt;P&gt;One of our users is using a file encryption service on his Windows computer which was initially flagged as ransomware. I added the application to our Allowed Applications list but it is still getting flagged, and seems to be alternating between succeeding and failing quarantine. I'd assumed that adding the file to the allowed list would've stopped these detections and quarantines, and was wondering if I'm doing something wrong with going about using the allowed/blocked lists. I know I can create an exclusion for the application, but then what would the point be of the allowed list vs. exclusions? Appreciate any insight into this.&lt;/P&gt;</description>
    <pubDate>Fri, 11 Mar 2022 17:29:42 GMT</pubDate>
    <dc:creator>vendeville_lj</dc:creator>
    <dc:date>2022-03-11T17:29:42Z</dc:date>
    <item>
      <title>Allowed Application Still Being Quarantined</title>
      <link>https://community.cisco.com/t5/endpoint-security/allowed-application-still-being-quarantined/m-p/4568964#M6753</link>
      <description>&lt;P&gt;One of our users is using a file encryption service on his Windows computer which was initially flagged as ransomware. I added the application to our Allowed Applications list but it is still getting flagged, and seems to be alternating between succeeding and failing quarantine. I'd assumed that adding the file to the allowed list would've stopped these detections and quarantines, and was wondering if I'm doing something wrong with going about using the allowed/blocked lists. I know I can create an exclusion for the application, but then what would the point be of the allowed list vs. exclusions? Appreciate any insight into this.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Mar 2022 17:29:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/allowed-application-still-being-quarantined/m-p/4568964#M6753</guid>
      <dc:creator>vendeville_lj</dc:creator>
      <dc:date>2022-03-11T17:29:42Z</dc:date>
    </item>
    <item>
      <title>Re: Allowed Application Still Being Quarantined</title>
      <link>https://community.cisco.com/t5/endpoint-security/allowed-application-still-being-quarantined/m-p/4572460#M6760</link>
      <description>&lt;P&gt;I briefly checked the website of the vendor. You better create a wildcard exclusion for encrypted files “*.axx” , as stated in the officical post." AxCrypt encrypted files should have a “.axx” file extension. So AxCrypt once encrypts the file, then the file will be renamed to “&lt;STRONG&gt;filename-originalextension.axx”&lt;/STRONG&gt;."&lt;/P&gt;</description>
      <pubDate>Thu, 17 Mar 2022 09:00:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/allowed-application-still-being-quarantined/m-p/4572460#M6760</guid>
      <dc:creator>David Janulik</dc:creator>
      <dc:date>2022-03-17T09:00:14Z</dc:date>
    </item>
    <item>
      <title>Re: Allowed Application Still Being Quarantined</title>
      <link>https://community.cisco.com/t5/endpoint-security/allowed-application-still-being-quarantined/m-p/4576394#M6767</link>
      <description>&lt;P&gt;So the application is allowed, but the encrypting of the files is what's flagging Secure Endpoint. Thanks for the info, and I'll get an exclusion created.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2022 18:58:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/allowed-application-still-being-quarantined/m-p/4576394#M6767</guid>
      <dc:creator>vendeville_lj</dc:creator>
      <dc:date>2022-03-22T18:58:48Z</dc:date>
    </item>
  </channel>
</rss>

