<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What happens to the file while dynamic analyis is being performed? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/what-happens-to-the-file-while-dynamic-analyis-is-being/m-p/4523689#M1086038</link>
    <description>&lt;P&gt;Thank you for your reply. I was thinking the same, but could not confirm as no Cisco document clearly says this.&lt;/P&gt;&lt;P&gt;Appreciate it.&lt;/P&gt;</description>
    <pubDate>Sat, 25 Dec 2021 05:22:31 GMT</pubDate>
    <dc:creator>muthumohan</dc:creator>
    <dc:date>2021-12-25T05:22:31Z</dc:date>
    <item>
      <title>What happens to the file while dynamic analyis is being performed?</title>
      <link>https://community.cisco.com/t5/network-security/what-happens-to-the-file-while-dynamic-analyis-is-being/m-p/4514679#M1085590</link>
      <description>&lt;P&gt;In FTD, while the file is being analyzed in the sandbox by ThreatGrid, when happens to file in transit?&lt;/P&gt;&lt;P&gt;Please let me know if this is correct:&lt;/P&gt;&lt;P&gt;If the file policy rule action is "Malware Cloud Lookup", I believe the file is sent to the end user and a malware event will be generated once the threat-score comes from TG and the file is determined to be a malware.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My real question is, if the file policy rule action is "Malware Block", what does the end user see, while the file is being analyzed by Threatgrid? Does he get 99% of the file and wait for the last 1% till TG sends back the threat-score?&lt;/P&gt;&lt;P&gt;I believe TG can take more than 15 minutes to complete the analysis. Does this mean the client will have to hold the TCP connection, say FTP, open till the threat-score comes back from TG? What is the deal here?&lt;/P&gt;&lt;P&gt;Thanks and appreciate any help. No where in Cisco documentation explain this part.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 07 Dec 2021 17:16:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-happens-to-the-file-while-dynamic-analyis-is-being/m-p/4514679#M1085590</guid>
      <dc:creator>muthumohan</dc:creator>
      <dc:date>2021-12-07T17:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: What happens to the file while dynamic analyis is being performed?</title>
      <link>https://community.cisco.com/t5/network-security/what-happens-to-the-file-while-dynamic-analyis-is-being/m-p/4516138#M1085671</link>
      <description>&lt;P&gt;Block Malware will only occur if the file disposition of the SHA256 (From local cache or AMP) is malicious. If the file is unknown then it will be send to ThreatGrid for analysis. While the analysis is taking place, the file is allowed through the firewall and is not held "hostage" If analysis determines that the unknown file is malicious, then a retrospective event will be triggered for this file.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope this helps!&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Dec 2021 16:58:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-happens-to-the-file-while-dynamic-analyis-is-being/m-p/4516138#M1085671</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2021-12-09T16:58:10Z</dc:date>
    </item>
    <item>
      <title>Re: What happens to the file while dynamic analyis is being performed?</title>
      <link>https://community.cisco.com/t5/network-security/what-happens-to-the-file-while-dynamic-analyis-is-being/m-p/4523689#M1086038</link>
      <description>&lt;P&gt;Thank you for your reply. I was thinking the same, but could not confirm as no Cisco document clearly says this.&lt;/P&gt;&lt;P&gt;Appreciate it.&lt;/P&gt;</description>
      <pubDate>Sat, 25 Dec 2021 05:22:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-happens-to-the-file-while-dynamic-analyis-is-being/m-p/4523689#M1086038</guid>
      <dc:creator>muthumohan</dc:creator>
      <dc:date>2021-12-25T05:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: What happens to the file while dynamic analyis is being performed?</title>
      <link>https://community.cisco.com/t5/network-security/what-happens-to-the-file-while-dynamic-analyis-is-being/m-p/4526542#M1086173</link>
      <description>&lt;P&gt;My pleasure! I have submitted an enhancement with the documentation team to update our documentation. Now, if you your question has been answered, please mark the thread as resolved &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Jan 2022 19:44:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/what-happens-to-the-file-while-dynamic-analyis-is-being/m-p/4526542#M1086173</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2022-01-04T19:44:22Z</dc:date>
    </item>
  </channel>
</rss>

