cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1900
Views
0
Helpful
2
Replies

AMP4E clean disposition: ClamAV scanning?

cpaquet
Level 1
Level 1

If AMP4E receives a disposition: CLEAN regarding a fingerprint sent to the cloud, will AMP4E still have that file scanned through the builtin Anti-Virus?

Thanks.

2 Replies 2

Wojciech Cecot
Cisco Employee
Cisco Employee

Hi,

It will be scanned, however when it comes to CLEAN disposition, no matter what will be verdict of the offline engine TETRA, it will be not quarantined.

-Wojciech

Troja007
Cisco Employee
Cisco Employee

Hello @cpaquet,

AMP4E uses 4 different types of caches to avoid multiple scanning fo files. AMP hashes files and does a lookup in the local cache. If it is already in the cache and the limits are not reached, AMP does not scan and also does no cloud lookup.

 

AMP Cache.png

 

 

 

 

 

Cheers,

Thorsten