cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3941
Views
7
Helpful
3
Replies

Can AMP kill and already running malicious process?

keitholsen
Level 1
Level 1

Hello,

If AMP detects a malicious executable that's already running, will it kill the process, or can it only prevent new instances from starting?

Thanks!

Keith

1 Accepted Solution

Accepted Solutions

csco12589127
Level 1
Level 1

Block malware in real time

AMP automatically detects and blocks threats in real time using global data analytics, machine learning, fuzzy fingerprinting, rootkit scanning, and a built-in antivirus engine.

From Cisco:Cisco Advanced Malware Protection (AMP) for Endpoints - Cisco

AMP scans continiously and blocks somehow if any found.

View solution in original post

3 Replies 3

csco12589127
Level 1
Level 1

Block malware in real time

AMP automatically detects and blocks threats in real time using global data analytics, machine learning, fuzzy fingerprinting, rootkit scanning, and a built-in antivirus engine.

From Cisco:Cisco Advanced Malware Protection (AMP) for Endpoints - Cisco

AMP scans continiously and blocks somehow if any found.

brmcmaho
Cisco Employee
Cisco Employee

The AMP for Endpoints connector is able to terminate processes if they are found to be malicious, yes.  Note the "Monitor Process Execution" setting under the File tab of your AMP policy settings.

sofian.said
Level 1
Level 1

Yes AMP will be able to kill the process