<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Block malware only using Local Malware Analysis in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/block-malware-only-using-local-malware-analysis/m-p/3224775#M926407</link>
    <description>&lt;P&gt;has anyone tried blocking malware just with local malware analysis enabled in the file policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Vaibhav&lt;/P&gt;</description>
    <pubDate>Thu, 30 Nov 2017 00:24:17 GMT</pubDate>
    <dc:creator>vaibhav.parlekar1</dc:creator>
    <dc:date>2017-11-30T00:24:17Z</dc:date>
    <item>
      <title>Block malware only using Local Malware Analysis</title>
      <link>https://community.cisco.com/t5/network-security/block-malware-only-using-local-malware-analysis/m-p/3223393#M926406</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;As per the documentation FireAMP blocks malware based on known hash and Firepower and can hold the file for 30 secs to get the verdict. In case if the verdict is unknown by FireAMP then can we use the ClamAV engine which is part of local malware analysis to block the malware inline on the network. Or is the file already sent in the network post FireAMP lookup.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are trying to reduce the no. of unknown files in the network and block them at the network level. I see the block malware option in the file-blocking policy with local malware analysis option. Just wanted to confirm before enabling the check.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help on the same is appreciated.&lt;/P&gt;
&lt;P&gt;Vaibhav&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:50:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-malware-only-using-local-malware-analysis/m-p/3223393#M926406</guid>
      <dc:creator>vaibhav.parlekar1</dc:creator>
      <dc:date>2020-02-21T14:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: Block malware only using Local Malware Analysis</title>
      <link>https://community.cisco.com/t5/network-security/block-malware-only-using-local-malware-analysis/m-p/3224775#M926407</link>
      <description>&lt;P&gt;has anyone tried blocking malware just with local malware analysis enabled in the file policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Vaibhav&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2017 00:24:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/block-malware-only-using-local-malware-analysis/m-p/3224775#M926407</guid>
      <dc:creator>vaibhav.parlekar1</dc:creator>
      <dc:date>2017-11-30T00:24:17Z</dc:date>
    </item>
  </channel>
</rss>

