<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Automatic Isolation didn't happen with retrospective detection in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/automatic-isolation-didn-t-happen-with-retrospective-detection/m-p/5131093#M8403</link>
    <description>&lt;P&gt;I think its based on the same logic as Forensic Snapshot which is also part of Automated Actions. The automated actions will fire up based on the fact if the machine is compromised or not there is few other things in to that but the main part is being &lt;STRONG&gt;compromised&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;So if there is event on your endpoint lets say malicious file and that file&amp;nbsp; was successfully quarantined then we did the job right and removed the potential threat, hence the machine is not compromised. But in case quarantine failed where we don't know where the file is or why we failed that machine is consider as compromised and then automated actions should trigger. &lt;BR /&gt;&lt;BR /&gt;Posted this couple years ago that explain the whole process. Hope that helps.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/secure-endpoint/217463-automated-actions-forensic-snapshot.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/secure-endpoint/217463-automated-actions-forensic-snapshot.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or Video : &lt;A href="https://youtu.be/dONLRCnDTGA" target="_blank" rel="noopener"&gt;https://youtu.be/dONLRCnDTGA&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 14 Jun 2024 17:59:44 GMT</pubDate>
    <dc:creator>Roman Valenta</dc:creator>
    <dc:date>2024-06-14T17:59:44Z</dc:date>
    <item>
      <title>Automatic Isolation didn't happen with retrospective detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/automatic-isolation-didn-t-happen-with-retrospective-detection/m-p/5130947#M8401</link>
      <description>&lt;P&gt;We had an endpoint automatically isolate with a high severity retrospective detection, as per our settings.&amp;nbsp;&lt;/P&gt;&lt;P&gt;A couple days later, the same endpoint had another high severity retrospective detection but there was no attempt by the console to automatically isolate.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the first instance, the file quarantine failed, in the second, the quarantine was successful; does this distinction account for the change in behaviour?&amp;nbsp; ie, automatic isolation won't be triggered with a retrospective detection that is successfully quarantined?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 15:34:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/automatic-isolation-didn-t-happen-with-retrospective-detection/m-p/5130947#M8401</guid>
      <dc:creator>Chris05</dc:creator>
      <dc:date>2024-06-14T15:34:03Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Isolation didn't happen with retrospective detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/automatic-isolation-didn-t-happen-with-retrospective-detection/m-p/5130990#M8402</link>
      <description>I feel like that's actually intentional.&lt;BR /&gt;But strangely enough the help has nothing about the Isolate automated action.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Fri, 14 Jun 2024 16:29:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/automatic-isolation-didn-t-happen-with-retrospective-detection/m-p/5130990#M8402</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2024-06-14T16:29:16Z</dc:date>
    </item>
    <item>
      <title>Re: Automatic Isolation didn't happen with retrospective detection</title>
      <link>https://community.cisco.com/t5/endpoint-security/automatic-isolation-didn-t-happen-with-retrospective-detection/m-p/5131093#M8403</link>
      <description>&lt;P&gt;I think its based on the same logic as Forensic Snapshot which is also part of Automated Actions. The automated actions will fire up based on the fact if the machine is compromised or not there is few other things in to that but the main part is being &lt;STRONG&gt;compromised&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;So if there is event on your endpoint lets say malicious file and that file&amp;nbsp; was successfully quarantined then we did the job right and removed the potential threat, hence the machine is not compromised. But in case quarantine failed where we don't know where the file is or why we failed that machine is consider as compromised and then automated actions should trigger. &lt;BR /&gt;&lt;BR /&gt;Posted this couple years ago that explain the whole process. Hope that helps.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/secure-endpoint/217463-automated-actions-forensic-snapshot.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/secure-endpoint/217463-automated-actions-forensic-snapshot.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;or Video : &lt;A href="https://youtu.be/dONLRCnDTGA" target="_blank" rel="noopener"&gt;https://youtu.be/dONLRCnDTGA&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2024 17:59:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/automatic-isolation-didn-t-happen-with-retrospective-detection/m-p/5131093#M8403</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2024-06-14T17:59:44Z</dc:date>
    </item>
  </channel>
</rss>

