<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Malware lookup - More analysis for management in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/malware-lookup-more-analysis-for-management/m-p/3076421#M43193</link>
    <description>&lt;P&gt;We (like anyone) get a ton of malware via SMTP. It gets blocked but I have no way to report to management what the malware was, what the business risk is, etc.&lt;/P&gt;
&lt;P&gt;Cisco support said to turn on capture so it can get the file on Firesight, but still there is no way I can see to give me a full "This was a Locky variant that has a CVE of xxx.x, you can read more on this here"&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Surely there is a place to go in Talos or via the actual SHA value to see what the malware was' no?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Bob James&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 13:45:41 GMT</pubDate>
    <dc:creator>bjames</dc:creator>
    <dc:date>2019-03-10T13:45:41Z</dc:date>
    <item>
      <title>Malware lookup - More analysis for management</title>
      <link>https://community.cisco.com/t5/network-security/malware-lookup-more-analysis-for-management/m-p/3076421#M43193</link>
      <description>&lt;P&gt;We (like anyone) get a ton of malware via SMTP. It gets blocked but I have no way to report to management what the malware was, what the business risk is, etc.&lt;/P&gt;
&lt;P&gt;Cisco support said to turn on capture so it can get the file on Firesight, but still there is no way I can see to give me a full "This was a Locky variant that has a CVE of xxx.x, you can read more on this here"&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Surely there is a place to go in Talos or via the actual SHA value to see what the malware was' no?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Bob James&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:45:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/malware-lookup-more-analysis-for-management/m-p/3076421#M43193</guid>
      <dc:creator>bjames</dc:creator>
      <dc:date>2019-03-10T13:45:41Z</dc:date>
    </item>
    <item>
      <title>If it is a black listed IP</title>
      <link>https://community.cisco.com/t5/network-security/malware-lookup-more-analysis-for-management/m-p/3076422#M43196</link>
      <description>&lt;P&gt;If it is a black listed IP (aka "Security Intelligence") it will get blocked before you can even pull it. As a result, there is no way to tell which malware it even was.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;If you turn off a lot of the protective measures, like security intelligence, you'll get prettier reports, since you are then relying on your last level of defence to detect the malware - but I wouldn't do it.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 06:24:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/malware-lookup-more-analysis-for-management/m-p/3076422#M43196</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2017-01-31T06:24:26Z</dc:date>
    </item>
    <item>
      <title>Same doesn't hold true for</title>
      <link>https://community.cisco.com/t5/network-security/malware-lookup-more-analysis-for-management/m-p/3076423#M43199</link>
      <description>&lt;P&gt;Same doesn't hold true for retrospective events.... The issue is we need to understand what the threats are;' they are getting the hash or looking at it retrospectively, so you can't tell me they don't know what the malware/vulnerability is.&lt;/P&gt;
&lt;P&gt;http://www.talosintelligence.com/amp-naming/&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;There is a naming convention site that helps but doesn't help me describe to management what the threat vector is, how we can plan an incident response (if one gets through), or anything other IPS types systems provide.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2017 15:18:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/malware-lookup-more-analysis-for-management/m-p/3076423#M43199</guid>
      <dc:creator>bjames</dc:creator>
      <dc:date>2017-01-31T15:18:18Z</dc:date>
    </item>
  </channel>
</rss>

