<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco AMP for Endpoints versus Cisco Malware Analytics in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-for-endpoints-versus-cisco-malware-analytics/m-p/5310491#M8914</link>
    <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1297969"&gt;@Mitrixsen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cisco Secure Endpoint is an endpoint protection solution that monitor files and activity on devices in real time, using &lt;EM&gt;cloud based&lt;/EM&gt; threat inteligence from Talos to detect/block threats. When it encounters a suspicious file it can’t fully assess, so it forwards it to Cisco Secure malware naalytic (formerly Threat Grid), which is a separate sandboxing platform that perform deep analysis but in a controled environment.&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/fireamp-endpoints/datasheet-c78-733181.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/fireamp-endpoints/datasheet-c78-733181.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/site/us/en/products/security/security-analytics/malware-analytics/index.html" target="_blank"&gt;https://www.cisco.com/site/us/en/products/security/security-analytics/malware-analytics/index.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Jul 2025 08:48:49 GMT</pubDate>
    <dc:creator>M02@rt37</dc:creator>
    <dc:date>2025-07-17T08:48:49Z</dc:date>
    <item>
      <title>Cisco AMP for Endpoints versus Cisco Malware Analytics</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-for-endpoints-versus-cisco-malware-analytics/m-p/5310482#M8913</link>
      <description>&lt;P&gt;Hello, everyone.&lt;/P&gt;
&lt;P&gt;I am studying security for my ENCOR exam and I have a question regarding the Cisco AMP4E (or secure endpoint) and Cisco Malware Analytics (or Threat Grid) appliances. My book defines Malware Analytics as following:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"Cisco Secure Malware Analytics, formerly Threat Grid, is a solution that can perform&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;static file analysis (for example, checking filenames, MD5 checksums, file types, and so on)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;as well as dynamic file analysis (also known as behavioral analysis) by running the files in a&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;controlled and monitored sandbox environment to observe and analyze the behavior against&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;millions of samples and billions of malware artifacts to determine whether it is malware or&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;not. Behavioral analysis is combined with threat intelligence feeds from Talos as well as with&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;existing security technologies to protect against known and unknown attacks.&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;I am wondering, how is Malware Analytics different from AMP? From what I understand about AMP, it's a service that runs in the cloud (or in network devices) that collects information from endpoints that also run the AMP software. For example, if a file is downloaded, it's sent to the AMP cloud where it's checked for its reputation, malware, and so on. If it's not sure, it can also run the file in a sandbox to determine it's behaviour. In the case of AMP for endpoints, the goal is to keep the endpoint safe from any malicious files.&lt;/P&gt;
&lt;P&gt;Maybe I am just confusing these two, so could someone please provide me with some clear distinction, or possibly explain what I got wrong about these two?&lt;/P&gt;
&lt;P&gt;Thank you.&lt;BR /&gt;David&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 08:13:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-for-endpoints-versus-cisco-malware-analytics/m-p/5310482#M8913</guid>
      <dc:creator>Mitrixsen</dc:creator>
      <dc:date>2025-07-17T08:13:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP for Endpoints versus Cisco Malware Analytics</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-for-endpoints-versus-cisco-malware-analytics/m-p/5310491#M8914</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1297969"&gt;@Mitrixsen&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cisco Secure Endpoint is an endpoint protection solution that monitor files and activity on devices in real time, using &lt;EM&gt;cloud based&lt;/EM&gt; threat inteligence from Talos to detect/block threats. When it encounters a suspicious file it can’t fully assess, so it forwards it to Cisco Secure malware naalytic (formerly Threat Grid), which is a separate sandboxing platform that perform deep analysis but in a controled environment.&lt;/P&gt;
&lt;P&gt;--&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/fireamp-endpoints/datasheet-c78-733181.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/fireamp-endpoints/datasheet-c78-733181.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/site/us/en/products/security/security-analytics/malware-analytics/index.html" target="_blank"&gt;https://www.cisco.com/site/us/en/products/security/security-analytics/malware-analytics/index.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 08:48:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-for-endpoints-versus-cisco-malware-analytics/m-p/5310491#M8914</guid>
      <dc:creator>M02@rt37</dc:creator>
      <dc:date>2025-07-17T08:48:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco AMP for Endpoints versus Cisco Malware Analytics</title>
      <link>https://community.cisco.com/t5/endpoint-security/cisco-amp-for-endpoints-versus-cisco-malware-analytics/m-p/5310622#M8916</link>
      <description>&lt;P&gt;Another thing to remember is tricky question when it comes to these two solutions. In integrations such as ESA and WSA these two will be referenced as:&lt;/P&gt;
&lt;P&gt;File Reputation Server --- &amp;gt; Secure Endpoint either Cloud or Private Appliance (virtual or physical)&lt;/P&gt;
&lt;P&gt;File Analysis Server --- &amp;gt; Secure Malware Analytic aka Threat Grid aka SandBox to detonate malicious files again&amp;nbsp;either Cloud or Private (physical only)&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2025 13:01:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/cisco-amp-for-endpoints-versus-cisco-malware-analytics/m-p/5310622#M8916</guid>
      <dc:creator>Roman Valenta</dc:creator>
      <dc:date>2025-07-17T13:01:30Z</dc:date>
    </item>
  </channel>
</rss>

