<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help with 2 alerts in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/need-help-with-2-alerts/m-p/4814056#M7465</link>
    <description>&lt;P&gt;Thanks, anyone know anything about the firefox detection? All our end points flagged firefox and it's currently blocked by AMP.&lt;/P&gt;</description>
    <pubDate>Thu, 13 Apr 2023 20:37:15 GMT</pubDate>
    <dc:creator>FrankyB2</dc:creator>
    <dc:date>2023-04-13T20:37:15Z</dc:date>
    <item>
      <title>Need help with 2 alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/need-help-with-2-alerts/m-p/4814015#M7461</link>
      <description>&lt;P&gt;Hello everyone, 1st post here, we have been receiving a lot of alerts regarding firefox, see #2. Also I would like to know if #1 is a false positive,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Secure Endpoint found a total of &lt;STRONG&gt;1&lt;/STRONG&gt; events matching your subscription named &lt;STRONG&gt;Indications_of_compromised&lt;/STRONG&gt; since 2023-04-13 13:25:47 UTC.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;&amp;nbsp;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Event Type:&lt;/STRONG&gt; Cloud IOC&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Computer:&lt;/STRONG&gt; ld*e-laptop.*&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Hostname:&lt;/STRONG&gt; ld*e-laptop.*&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;IP:&lt;/STRONG&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Detection:&lt;/STRONG&gt; W32.082827C4A5.RET.SBX.TG&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;File:&lt;/STRONG&gt; MicrosoftEdge_X64_112.0.1722.39_112.0.1722.34.exe&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;File path:&lt;/STRONG&gt; file:///C%3A/Program%20Files%20%28x86%29/Microsoft/EdgeUpdate/Install/%7B411AF51C-D039-427C-8592-B0095C3613BF%7D/MicrosoftEdge_X64_112.0.1722.39_112.0.1722.34.exe&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Detection SHA-256:&lt;/STRONG&gt; 082827c4a5582f887901c4cce83a1aa9b8a4eb23835a434fc104bba745172a85&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Application SHA-256:&lt;/STRONG&gt; 9991ba022173f283ee99068b708f60ac5143fe0c81c9e3673cc7835b108a4f44&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Severity:&lt;/STRONG&gt; High&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Timestamp:&lt;/STRONG&gt; 2023-04-13 13:21:45 +0000 UTC&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Event Type:&lt;/STRONG&gt; Exploit Prevention&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Computer:&lt;/STRONG&gt; WKS-&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Hostname:&lt;/STRONG&gt; WKS-&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;IP:&lt;/STRONG&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;User:&lt;/STRONG&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;File:&lt;/STRONG&gt; firefox.exe&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;File path:&lt;/STRONG&gt; C:\Program Files\Mozilla Firefox\firefox.exe&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Detection SHA-256:&lt;/STRONG&gt; 5b2abf9947a12ff9cc3765e48d875d97752193fcbc5e2b89fdb3e138c3232568&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;By Application:&lt;/STRONG&gt; firefox.exe&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Application SHA-256:&lt;/STRONG&gt; 5b2abf9947a12ff9cc3765e48d875d97752193fcbc5e2b89fdb3e138c3232568&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;Timestamp:&lt;/STRONG&gt; 2023-04-06 21:17:06 +0000 UTC&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Thu, 13 Apr 2023 19:13:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/need-help-with-2-alerts/m-p/4814015#M7461</guid>
      <dc:creator>FrankyB2</dc:creator>
      <dc:date>2023-04-13T19:13:11Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with 2 alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/need-help-with-2-alerts/m-p/4814018#M7462</link>
      <description>For sure the first one is a false positive, see other posts in the community from today.&lt;BR /&gt;Should already be fixed in the backend.. now just waiting for it to propagate.&lt;BR /&gt;</description>
      <pubDate>Thu, 13 Apr 2023 19:20:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/need-help-with-2-alerts/m-p/4814018#M7462</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2023-04-13T19:20:27Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with 2 alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/need-help-with-2-alerts/m-p/4814056#M7465</link>
      <description>&lt;P&gt;Thanks, anyone know anything about the firefox detection? All our end points flagged firefox and it's currently blocked by AMP.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 20:37:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/need-help-with-2-alerts/m-p/4814056#M7465</guid>
      <dc:creator>FrankyB2</dc:creator>
      <dc:date>2023-04-13T20:37:15Z</dc:date>
    </item>
    <item>
      <title>Re: Need help with 2 alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/need-help-with-2-alerts/m-p/4814067#M7466</link>
      <description>&lt;P&gt;The Firefox SHA-256 (&lt;SPAN&gt;5b2abf9947a12ff9cc3765e48d875d97752193fcbc5e2b89fdb3e138c3232568&lt;/SPAN&gt;) is not related to the FP event from today.&lt;/P&gt;
&lt;P&gt;Although this is an&amp;nbsp;&lt;SPAN&gt;Exploit Prevention event, it is probably being generated because a 3rd party acting with Firefox and generating an unexpected behavior.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I suggest opening a TAC case to properly investigate. Our Cisco TAC team is ready to assist with the investigation.&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;Pedro M.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Apr 2023 20:50:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/need-help-with-2-alerts/m-p/4814067#M7466</guid>
      <dc:creator>pmedinac</dc:creator>
      <dc:date>2023-04-13T20:50:39Z</dc:date>
    </item>
  </channel>
</rss>

