cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3058
Views
0
Helpful
3
Replies

AMP Event details

abirajkwilson
Level 1
Level 1

HI All,

 

There are many event types available in filter tab.Do we have any small definition about the event types example : Cloud IOC,etc

3 Replies 3

Troja007
Cisco Employee
Cisco Employee

Hello @abirajkwilson,

not 100% sure what you need in detail.

 

Cloud IOC: this is not a "static event". The endpoint monitors disk, process and network activity. This activity is processed in the AMP backend and generates the IOC Events. They are different to normal Threat Events. An IOC event indicates a problem with and endpoint you should investigate.

 

Pleas come back to me if yo have more questions.

 

Greetings,

Thorsten

HI @Troja007,

the reply you provided was good for Cloud IOC Events. Is there definitions/information(Cisco KB link) available like you have provided(Cloud IOC) for other types of events and subdivisions of events? Detected threats>>Malicious Activity Detection,Exploit prevention,etc IOC>>cloud,multiple infected files,potential dropper infection,etc

Hello @abirajkwilson,

for Threat Events and the naming, you can take a look here: https://www.talosintelligence.com/amp-naming

Regarding other Events like ExPloit Prevention: What information you need? Or, what information you need to understand the Event?

 

Just to be sure, you want to have a longer description about any Threat Type? Which information in detail you are looking for. Maybe information how you should handle the information?

Just trying to understand your needs.

 

Greetings,

Thorsten

 

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: