<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Multiple Secure Endpoint Alerts in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5055647#M8266</link>
    <description>&lt;P&gt;Hi, in the last few hours our Secure Endpoint has alerted to hundreds of events associated with "&lt;SPAN class=""&gt;Gen:Variant.Jatommy.3.3433". While the files are being quarantined in most cases, i believe this may be a false positive, is anyone else seeing these alerts?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;</description>
    <pubDate>Wed, 03 Apr 2024 14:51:56 GMT</pubDate>
    <dc:creator>johnmac</dc:creator>
    <dc:date>2024-04-03T14:51:56Z</dc:date>
    <item>
      <title>Multiple Secure Endpoint Alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5055647#M8266</link>
      <description>&lt;P&gt;Hi, in the last few hours our Secure Endpoint has alerted to hundreds of events associated with "&lt;SPAN class=""&gt;Gen:Variant.Jatommy.3.3433". While the files are being quarantined in most cases, i believe this may be a false positive, is anyone else seeing these alerts?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 14:51:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5055647#M8266</guid>
      <dc:creator>johnmac</dc:creator>
      <dc:date>2024-04-03T14:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Secure Endpoint Alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5055662#M8267</link>
      <description>&lt;P&gt;I haven't yet... what sorts of files is it hitting on?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 15:04:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5055662#M8267</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2024-04-03T15:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Secure Endpoint Alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5055663#M8268</link>
      <description>&lt;P&gt;&lt;SPAN&gt;C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\b2fa8ab4e829625f.customDestinations-ms&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 15:09:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5055663#M8268</guid>
      <dc:creator>johnmac</dc:creator>
      <dc:date>2024-04-03T15:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Secure Endpoint Alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5055697#M8269</link>
      <description>&lt;P&gt;I am seeing the same thing on a smaller scale. I have only gotten a handful of alerts today. At least at this point.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 16:04:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5055697#M8269</guid>
      <dc:creator>mpdonovan</dc:creator>
      <dc:date>2024-04-03T16:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Secure Endpoint Alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5055704#M8270</link>
      <description>&lt;P&gt;I am seeing this happen today as well. All appear to be coming from the parent file msedge.exe. I am seeing two different hashes for this msedge.exe which both are coming up clean.&lt;/P&gt;&lt;P&gt;1d7e81e6a33c0dc5541770b414fb7bc9760141ec9b869dcd9466017292f99d1a&lt;/P&gt;&lt;P&gt;e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855&lt;/P&gt;&lt;P&gt;C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\LUHCRNBMS942Y9B7W95W.temp&lt;/P&gt;&lt;P&gt;C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ccba5a5986c77e43.customDestinations-ms&lt;/P&gt;&lt;P&gt;C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Y0FE6QYMR6IZ67O9NC0E.temp&lt;/P&gt;&lt;P&gt;C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\T6IWKQUHJLDEE9YHH41B.temp&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 16:11:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5055704#M8270</guid>
      <dc:creator>Alisabeth N</dc:creator>
      <dc:date>2024-04-03T16:11:19Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Secure Endpoint Alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5055716#M8271</link>
      <description>&lt;P&gt;TALOS is investigating.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 16:40:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5055716#M8271</guid>
      <dc:creator>Matthew Franks</dc:creator>
      <dc:date>2024-04-03T16:40:07Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Secure Endpoint Alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5055807#M8274</link>
      <description>&lt;P&gt;Does anyone know if this has officially been determined to be a False Positive?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Apr 2024 20:04:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5055807#M8274</guid>
      <dc:creator>tbduff001</dc:creator>
      <dc:date>2024-04-03T20:04:17Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Secure Endpoint Alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5056128#M8276</link>
      <description>&lt;P&gt;Hi Matthew, has there been any update from Talos on this?&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 08:41:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5056128#M8276</guid>
      <dc:creator>johnmac</dc:creator>
      <dc:date>2024-04-04T08:41:38Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Secure Endpoint Alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5056252#M8277</link>
      <description>&lt;P&gt;Good morning. Yes, it was determined to be a False Positive. Apologies for the delay on the update, the resolution came after I was out for the day.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;-Matt&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 11:33:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5056252#M8277</guid>
      <dc:creator>Matthew Franks</dc:creator>
      <dc:date>2024-04-04T11:33:46Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Secure Endpoint Alerts</title>
      <link>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5056259#M8278</link>
      <description>&lt;P&gt;Great, thanks for that Matthew.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Apr 2024 11:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/multiple-secure-endpoint-alerts/m-p/5056259#M8278</guid>
      <dc:creator>johnmac</dc:creator>
      <dc:date>2024-04-04T11:39:09Z</dc:date>
    </item>
  </channel>
</rss>

