<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AMSI Deleted for Windows Defender/Security in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4840261#M7555</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you already know the MsMPEng is a defender, and it is a trusted application the reasoning why this is getting triggered is because defender is modifying its registry keys and that is being flagged by the BP engine as potential thread.&lt;/P&gt;
&lt;P&gt;You can do two things here: &lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;#1:&lt;/STRONG&gt; You can add an custom exclusion for this. This will be done under exclusion there is an option to select Engine option where you should select Behavior Protection and chose either SHA256 or Path.&amp;nbsp; Also verify that Cisco Maintained exclusions are in place as well&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2671.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/185245iA79B42F56336A9B8/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_2671.png" alt="Screenshot_2671.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2672.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/185244i325645D114F8F488/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_2672.png" alt="Screenshot_2672.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;#2:&lt;/STRONG&gt; Ensure that the APDE signature is up to date.&lt;BR /&gt;&lt;BR /&gt;Hope this helped...&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Roman&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 22 May 2023 14:14:00 GMT</pubDate>
    <dc:creator>Roman Valenta</dc:creator>
    <dc:date>2023-05-22T14:14:00Z</dc:date>
    <item>
      <title>AMSI Deleted for Windows Defender/Security</title>
      <link>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4818883#M7490</link>
      <description>&lt;P&gt;We've had a handful of machines get flagged for the AMSI provider being deleted from the registry, and haven't been able to put a finger on the cause. The registry key being deleted looks like it's the one for Windows' built-in AV ( {2781761E-28E0-4109-99FE-B9D127C57AFE} ). All the flagged machines have their AMSI keys pointing set correctly for Secure Endpoint, and testing of uninstalling Secure Endpoint to go back to Windows Security has had the deleted key (listed above) be restored, and then get replaced once Secure Endpoint is reinstalled.&lt;/P&gt;&lt;P&gt;All the detected machines have had their connector versions upgraded recently, but for some the AMSI key deletion was detected within minutes of the upgrade, while several hours pass on other machines before getting flagged.&lt;/P&gt;&lt;P&gt;All scans have come back clean, and the vast majority of clients that had their connectors upgraded haven't triggered this, so we're trying to figure out if this is just a bug, or if there's actual suspicious activity going on.&lt;/P&gt;&lt;P&gt;If anyone's run into this before, or has advice for further investigation, it would be much appreciated.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 20:55:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4818883#M7490</guid>
      <dc:creator>vendeville_lj</dc:creator>
      <dc:date>2023-04-20T20:55:36Z</dc:date>
    </item>
    <item>
      <title>Re: AMSI Deleted for Windows Defender/Security</title>
      <link>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4820128#M7494</link>
      <description>&lt;P&gt;_&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 15:47:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4820128#M7494</guid>
      <dc:creator>ventaran</dc:creator>
      <dc:date>2023-04-25T15:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: AMSI Deleted for Windows Defender/Security</title>
      <link>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4820231#M7495</link>
      <description>&lt;P&gt;I put in a TAC case. If anything of value comes back, I will comment back.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 11:06:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4820231#M7495</guid>
      <dc:creator>ventaran</dc:creator>
      <dc:date>2023-04-24T11:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: AMSI Deleted for Windows Defender/Security</title>
      <link>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4821450#M7496</link>
      <description>&lt;P&gt;Still waiting on a TAC response. Not leaving anyone hanging.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 15:47:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4821450#M7496</guid>
      <dc:creator>ventaran</dc:creator>
      <dc:date>2023-04-25T15:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: AMSI Deleted for Windows Defender/Security</title>
      <link>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4821477#M7497</link>
      <description>&lt;P&gt;TAC response&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;We have confirmed through Talos that there is a new BP feature introduced which can now delete "Registry" values if a BP Signature with that specific action gets triggered and that is essentially why we see this causing issues only with 8.1.7.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN&gt;As most of these are actions taken against known and trusted AV solutions, much like in this case “MsMpEng.exe”, we can conclude these are false positives. There is an ongoing investigation with Talos to address these BP Engine false positives but as of right now, the known workaround that has worked for other customers is setting a BP engine exclusion:&lt;/SPAN&gt;"&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 16:32:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4821477#M7497</guid>
      <dc:creator>ventaran</dc:creator>
      <dc:date>2023-04-25T16:32:50Z</dc:date>
    </item>
    <item>
      <title>Re: AMSI Deleted for Windows Defender/Security</title>
      <link>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4821480#M7498</link>
      <description>&lt;P&gt;Thanks for checking this out and providing the information, it's much appreciated.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 16:44:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4821480#M7498</guid>
      <dc:creator>vendeville_lj</dc:creator>
      <dc:date>2023-04-25T16:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: AMSI Deleted for Windows Defender/Security</title>
      <link>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4821486#M7499</link>
      <description>&lt;P&gt;If you want, email me for the future - &lt;A href="mailto:ventaran@uhnj.org" target="_blank"&gt;ventaran@uhnj.org&lt;/A&gt;&amp;nbsp;or anyone who uses AMP and updates regularly. It would be great to have a group of folks who use the tool we can bounce issues/ideas off of.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2023 16:52:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4821486#M7499</guid>
      <dc:creator>ventaran</dc:creator>
      <dc:date>2023-04-25T16:52:57Z</dc:date>
    </item>
    <item>
      <title>Re: AMSI Deleted for Windows Defender/Security</title>
      <link>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4821537#M7500</link>
      <description>That's what this space is for...&lt;BR /&gt;&lt;BR /&gt;There is also a public WebEx space here:&lt;BR /&gt;&lt;A href="Https://eurl.io/#TmrReXaEj" target="_blank"&gt;Https://eurl.io/#TmrReXaEj&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 25 Apr 2023 19:05:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4821537#M7500</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2023-04-25T19:05:59Z</dc:date>
    </item>
    <item>
      <title>Re: AMSI Deleted for Windows Defender/Security</title>
      <link>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4840234#M7552</link>
      <description>&lt;P&gt;Hello, thanks for sharing this. But i still don't know how to set up this "BP engine exclusion" Can someone help with this?&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 13:14:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4840234#M7552</guid>
      <dc:creator>Systema Support</dc:creator>
      <dc:date>2023-05-22T13:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: AMSI Deleted for Windows Defender/Security</title>
      <link>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4840261#M7555</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you already know the MsMPEng is a defender, and it is a trusted application the reasoning why this is getting triggered is because defender is modifying its registry keys and that is being flagged by the BP engine as potential thread.&lt;/P&gt;
&lt;P&gt;You can do two things here: &lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;#1:&lt;/STRONG&gt; You can add an custom exclusion for this. This will be done under exclusion there is an option to select Engine option where you should select Behavior Protection and chose either SHA256 or Path.&amp;nbsp; Also verify that Cisco Maintained exclusions are in place as well&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2671.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/185245iA79B42F56336A9B8/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_2671.png" alt="Screenshot_2671.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2672.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/185244i325645D114F8F488/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot_2672.png" alt="Screenshot_2672.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;#2:&lt;/STRONG&gt; Ensure that the APDE signature is up to date.&lt;BR /&gt;&lt;BR /&gt;Hope this helped...&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Roman&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 14:14:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/amsi-deleted-for-windows-defender-security/m-p/4840261#M7555</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2023-05-22T14:14:00Z</dc:date>
    </item>
  </channel>
</rss>

