<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Suspicious smss.exe Parent Process in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922515#M7808</link>
    <description>&lt;P&gt;We are currently on version 8.1.7.21585 and we are also getting some of these.&lt;/P&gt;</description>
    <pubDate>Wed, 13 Sep 2023 06:16:16 GMT</pubDate>
    <dc:creator>thomasleite</dc:creator>
    <dc:date>2023-09-13T06:16:16Z</dc:date>
    <item>
      <title>Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922114#M7795</link>
      <description>&lt;P&gt;We are getting hundreds of these threat detections this morning in our environment. These are all considered "low" and the smss.exe file is clean (SHA-256:&amp;nbsp;56afe5133fdc5806ec6b19436f7b55f1499cfc94619740c171424fbcf7808fd3)&lt;/P&gt;&lt;P&gt;Seems to be triggered at logon.&amp;nbsp;Anyone else seeing these? Suspect a false positive. All scans have come back clean&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 14:47:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922114#M7795</guid>
      <dc:creator>jeremy.peace-hall</dc:creator>
      <dc:date>2023-09-12T14:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922161#M7796</link>
      <description>&lt;P&gt;Same here. Triaged the workstations and didn't find anything suspicious.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 16:21:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922161#M7796</guid>
      <dc:creator>GJ.NoscoICT</dc:creator>
      <dc:date>2023-09-12T16:21:34Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922213#M7797</link>
      <description>&lt;P&gt;We are currently looking in to this issue internally and investigating the event as it seems to be FP event triggered by Behavioral Protection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 17:30:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922213#M7797</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2023-09-12T17:30:26Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922249#M7798</link>
      <description>&lt;P&gt;Would i need to continuously check on this post in order to look for a solution? Also getting dozens of these alerts as of this morning.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 18:14:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922249#M7798</guid>
      <dc:creator>noahigros</dc:creator>
      <dc:date>2023-09-12T18:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922299#M7800</link>
      <description>&lt;P&gt;Can you guys please confirm the connector version on which you receiving this alert?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 19:57:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922299#M7800</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2023-09-12T19:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922300#M7801</link>
      <description>&lt;P&gt;Started seeing this shortly after upgrading to 8.2.1.21612.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 20:00:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922300#M7801</guid>
      <dc:creator>RHauke</dc:creator>
      <dc:date>2023-09-12T20:00:36Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922301#M7802</link>
      <description>&lt;P&gt;8.2.1.21612 is the version for all those connectors. We have about 60 alerts for this incident.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 20:00:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922301#M7802</guid>
      <dc:creator>noahigros</dc:creator>
      <dc:date>2023-09-12T20:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922302#M7803</link>
      <description>Hey Roman,&lt;BR /&gt;Seeing it on 8.2.1.21612,&lt;BR /&gt;SMSS and wininit.exe are both throwing it.&lt;BR /&gt;&lt;BR /&gt;Ken&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 12 Sep 2023 20:01:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922302#M7803</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2023-09-12T20:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922311#M7805</link>
      <description>&lt;P&gt;Thanks that's what I thought just wanted to be sure. Based on the response in our internal ticket at this time we believe this is only affecting AMP Version: 8.2.1.21612. The likely reason appears to be a BP build issue which we are working to resolve as soon as possible. I will&amp;nbsp; keep you guys updated once anything new comes up.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 20:12:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922311#M7805</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2023-09-12T20:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922312#M7806</link>
      <description>&lt;P&gt;thank you, Roman. Would it be okay to resolve the alerts? or should we keep them open until your team says we are good? I appreciate it.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Sep 2023 20:15:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922312#M7806</guid>
      <dc:creator>noahigros</dc:creator>
      <dc:date>2023-09-12T20:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922515#M7808</link>
      <description>&lt;P&gt;We are currently on version 8.1.7.21585 and we are also getting some of these.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 06:16:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4922515#M7808</guid>
      <dc:creator>thomasleite</dc:creator>
      <dc:date>2023-09-13T06:16:16Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4923291#M7810</link>
      <description>&lt;P&gt;HI Roman,&amp;nbsp;&lt;BR /&gt;Do you have an up date on the progress?&lt;/P&gt;
&lt;P&gt;Br&lt;/P&gt;
&lt;P&gt;THomas&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 08:08:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4923291#M7810</guid>
      <dc:creator>tbrobech</dc:creator>
      <dc:date>2023-09-14T08:08:26Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4923454#M7811</link>
      <description>&lt;P&gt;I look up the escalation ticket and as of this morning the team that is working on this reported that they are still working in the back end to sort it out this issue. As of right now this would be most likely mitigated with new BP signature update.&lt;/P&gt;
&lt;P&gt;As more cases arrived we got some data to provide them including some artifacts as well so hopefully the resolution will be soon. I will let you guys know once I know little bit more than this.&lt;/P&gt;
&lt;P&gt;As far for 8.1.7.21585 we did got couple cases regarding this release as well and since this is related to newer BP signature update it's expected.&lt;/P&gt;
&lt;P&gt;Thank you guys for your patience we are staying on top of this and trying to resolve this matter as soon as we can.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 13:15:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4923454#M7811</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2023-09-14T13:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4923503#M7812</link>
      <description>&lt;P&gt;For my organization, this began once I approved Endpoint Security Client ver 8.2.1.21612 2 days ago.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 14:58:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4923503#M7812</guid>
      <dc:creator>jkoch2</dc:creator>
      <dc:date>2023-09-14T14:58:07Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4923649#M7814</link>
      <description>&lt;P&gt;Hey Guys I just checked my home PC with 8.2.x installed and I noticed my last event was on 9/12 since then there was 3 BP signature updates and no more events. The latest one has serial # 11044. If anyone still receiving these alerts can you please check your BP definition on the machine that still reports this issue?&lt;BR /&gt;&lt;BR /&gt;You can do that via CMD line just navigate to the AMP directory and run : &lt;STRONG&gt;ampcli posture&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;C:\WINDOWS\system32&amp;gt;cd C:\Program Files\Cisco\AMP\8.2.1.21612

C:\Program Files\Cisco\AMP\8.2.1.21612&amp;gt;ampcli posture
{"agent_uuid":"cxxxxxe-4294-8xx5-f306xxxxxxea9","connected":true,"connector_version":"8.2.1","engines":[{"definitions":[{"last_successful_update":1694717388,"name":"Tetra","timestamp":1694698347,"version":91242}],"enabled":true,"name":"Tetra"},{"enabled":true,"name":"Spero"},{"enabled":true,"name":"Ethos"},{"definitions":[{"name":"BP","timestamp":1694717956,"version":11044}],"enabled":true,"name":"BP"},{"definitions":[{"name":"SCS","timestamp":1694717910,"version":11044}],"enabled":true,"name":"SCS"}],"last_scan":1694703038,"last_scan_status":true,"protect_file_mode":true,"protect_process_mode":true,"running":true}
C:\Program Files\Cisco\AMP\8.2.1.21612&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then look for the line:&lt;/P&gt;
&lt;P&gt;"name":"BP","timestamp":1694717956,"version":11044 &amp;lt;&amp;lt; ------------------&lt;/P&gt;
&lt;P&gt;Nobody yet responded to our escalation ticket but I guess its due to different time zone that these guys work in based on the time they usually respond back.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 19:34:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4923649#M7814</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2023-09-14T19:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4923654#M7815</link>
      <description>&lt;P&gt;Some of our clients just started to update to 11044. We are still getting a bunch of these smss.exe detections but all of them are on clients still running 11011. Hopefully by tomorrow morning these will cease as the clients get the new definition update (11044). Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 19:42:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4923654#M7815</guid>
      <dc:creator>jeremy.peace-hall</dc:creator>
      <dc:date>2023-09-14T19:42:29Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4923656#M7816</link>
      <description>&lt;P&gt;So it now confirmed as well. We just got another update that they did release BP update late last night to resolve the remaining signatures that were still causing FPs for some of our customers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 19:49:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4923656#M7816</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2023-09-14T19:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4923659#M7817</link>
      <description>&lt;P&gt;Hey Roman,&amp;nbsp;&lt;/P&gt;&lt;P&gt;per your update confirming that they did release a new BP update to resolve the remaining signatures that were causing FPs. Will this mean i can resolve the ones i have now?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 19:54:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4923659#M7817</guid>
      <dc:creator>noahigros</dc:creator>
      <dc:date>2023-09-14T19:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4923676#M7818</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here's my output&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/474196"&gt;@Roman Valenta&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;C:\Program Files\Cisco\AMP\8.2.1.21612&amp;gt;ampcli posture&lt;BR /&gt;"connected":true,"connector_version":"8.2.1","engines":[{"definitions":[{"last_successful_update":1694717002,"name":"Tetra","timestamp":1694698347,"version":91242}],"enabled":true,"name":"Tetra"},{"enabled":true,"name":"Spero"},{"enabled":true,"name":"Ethos"},{"definitions":[{"name":"BP","timestamp":1694720952,"version":11044}],"enabled":true,"name":"BP"},{"definitions":[{"name":"SCS","timestamp":1694720935,"version":11044}],"enabled":true,"name":"SCS"}],"last_scan":1692637158,"last_scan_status":true,"protect_file_mode":true,"protect_process_mode":true,"running":true}&lt;/P&gt;</description>
      <pubDate>Thu, 14 Sep 2023 20:20:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4923676#M7818</guid>
      <dc:creator>Bbailey2</dc:creator>
      <dc:date>2023-09-14T20:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: Suspicious smss.exe Parent Process</title>
      <link>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4924085#M7819</link>
      <description>&lt;P&gt;You mean resolve them in your Inbox? if so then YES.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2023 12:04:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/suspicious-smss-exe-parent-process/m-p/4924085#M7819</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2023-09-15T12:04:01Z</dc:date>
    </item>
  </channel>
</rss>

