<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: fp on svchost.exe on Windows 2019 servers? in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585555#M6792</link>
    <description>&lt;P&gt;Having this on many of our Desktops and Servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Apr 2022 20:19:29 GMT</pubDate>
    <dc:creator>philippaisley</dc:creator>
    <dc:date>2022-04-04T20:19:29Z</dc:date>
    <item>
      <title>fp on svchost.exe on Windows 2019 servers?</title>
      <link>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585527#M6786</link>
      <description>&lt;P&gt;Hey all,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;are you seeing an FP on svchost.exe?&amp;nbsp; Mostly Cloud.IOCs...&lt;/P&gt;
&lt;P&gt;Ken&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 19:20:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585527#M6786</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2022-04-04T19:20:30Z</dc:date>
    </item>
    <item>
      <title>Re: fp on svchost.exe on Windows 2019 servers?</title>
      <link>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585542#M6787</link>
      <description>&lt;P&gt;We are seeing it on multiple windows machines&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 19:54:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585542#M6787</guid>
      <dc:creator>Brian.Cochran</dc:creator>
      <dc:date>2022-04-04T19:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: fp on svchost.exe on Windows 2019 servers?</title>
      <link>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585551#M6789</link>
      <description>&lt;P&gt;It has been flagged on all my servers, But no Windows desktop machines.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 20:01:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585551#M6789</guid>
      <dc:creator>jwilliams2</dc:creator>
      <dc:date>2022-04-04T20:01:27Z</dc:date>
    </item>
    <item>
      <title>Re: fp on svchost.exe on Windows 2019 servers?</title>
      <link>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585552#M6790</link>
      <description>&lt;P&gt;Is this a false positive? A whole bunch of machines on our network are being isolated due to this event.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 20:02:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585552#M6790</guid>
      <dc:creator>SReed2020</dc:creator>
      <dc:date>2022-04-04T20:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: fp on svchost.exe on Windows 2019 servers?</title>
      <link>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585554#M6791</link>
      <description>Thanks for the update.&lt;BR /&gt;</description>
      <pubDate>Mon, 04 Apr 2022 20:12:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585554#M6791</guid>
      <dc:creator>jwilliams2</dc:creator>
      <dc:date>2022-04-04T20:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: fp on svchost.exe on Windows 2019 servers?</title>
      <link>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585555#M6792</link>
      <description>&lt;P&gt;Having this on many of our Desktops and Servers.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 20:19:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585555#M6792</guid>
      <dc:creator>philippaisley</dc:creator>
      <dc:date>2022-04-04T20:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: fp on svchost.exe on Windows 2019 servers?</title>
      <link>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585556#M6793</link>
      <description>&lt;P&gt;Seeing the same, only on 2016/2019 Windows servers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Have undertaken what checks we can in the time and all coming back no threat.&lt;/P&gt;&lt;P&gt;Still digging.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 20:21:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585556#M6793</guid>
      <dc:creator>soup_dragon</dc:creator>
      <dc:date>2022-04-04T20:21:08Z</dc:date>
    </item>
    <item>
      <title>Re: fp on svchost.exe on Windows 2019 servers?</title>
      <link>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585558#M6794</link>
      <description>&lt;P&gt;Any update on this problem? We also have 2019 servers jumping into isolation mode regarding svchost fp.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 20:30:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585558#M6794</guid>
      <dc:creator>Rene Mueller</dc:creator>
      <dc:date>2022-04-04T20:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: fp on svchost.exe on Windows 2019 servers?</title>
      <link>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585561#M6795</link>
      <description>&lt;P&gt;Cisco advise False Positive&lt;/P&gt;&lt;P&gt;Cisco Secure Endpoint Announcement - False Positive detection&lt;BR /&gt;Cisco is aware of the false-positive detection related to svchost.exe. The single SHA-256 involved is cb19fd67b1d02......96cfe0ee0c6e45285436a1. The file disposition has been updated and Cisco is investigating the root cause. We apologize for any inconvenience this may have caused.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 20:39:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585561#M6795</guid>
      <dc:creator>soup_dragon</dc:creator>
      <dc:date>2022-04-04T20:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: fp on svchost.exe on Windows 2019 servers?</title>
      <link>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585563#M6796</link>
      <description>I put in a file reputation request on TalosIntelligence.com&lt;BR /&gt;Tweeted TalosIntelligence.&lt;BR /&gt;Opened a TAC case.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 04 Apr 2022 20:42:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585563#M6796</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2022-04-04T20:42:21Z</dc:date>
    </item>
    <item>
      <title>Re: fp on svchost.exe on Windows 2019 servers?</title>
      <link>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585577#M6797</link>
      <description>If you investigate it using Cisco Threat Response it comes up marked as a "Common SHA-256 Hash"&lt;BR /&gt;Nobody on Virus Total marks it bad.&lt;BR /&gt;Malwares.com marks it good.&lt;BR /&gt;&lt;BR /&gt;Yeah... its an FP...&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 04 Apr 2022 21:09:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/fp-on-svchost-exe-on-windows-2019-servers/m-p/4585577#M6797</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2022-04-04T21:09:21Z</dc:date>
    </item>
  </channel>
</rss>

