08-20-2019 02:02 PM
I am trying to get AMP for ESA set up on our IronPort C170 appliance running ASyncOS 11.0.3. I believe I have my settings correct, however, files that have a verdict of unknown are not being uploaded for analysis. Perhaps I'm missing something? I have made sure that file analysis is enabled for all supported file types. Any help would be greatly appreciated.
Solved! Go to Solution.
08-21-2019 07:51 AM
Hello,
In addition to what Pratham has already mentioned, an Unknown verdict does not automatically mean the file is uploaded to Threatgrid for File Analysis. There is a pre-classification process on the ESA where the file is further checked prior to upload for File Analysis, if there are additional markers where we deem it needs further scanning, then it is uploaded. If we look at the file and it appears safe, then we let it proceed onward without upload.
You should be able to go through the AMP logs to see exactly why/why not these files may have not been uploaded. Feel free to share some of the logs if needed as well and we can help confirm.
Thanks!
-Dennis M.
08-20-2019 10:41 PM
08-21-2019 07:51 AM
Hello,
In addition to what Pratham has already mentioned, an Unknown verdict does not automatically mean the file is uploaded to Threatgrid for File Analysis. There is a pre-classification process on the ESA where the file is further checked prior to upload for File Analysis, if there are additional markers where we deem it needs further scanning, then it is uploaded. If we look at the file and it appears safe, then we let it proceed onward without upload.
You should be able to go through the AMP logs to see exactly why/why not these files may have not been uploaded. Feel free to share some of the logs if needed as well and we can help confirm.
Thanks!
-Dennis M.
08-21-2019 09:03 AM
Thank you everyone for your help with this. In reviewing the AMP log, I found that it does show that the 'UNKNOWN' file was not sent for analysis and gives the reason as 'No active/dynamic contents exists'. In reading other posts and the documentation, I now understand that newer versions of AMP are designed to be smarter. When an unknown verdict is reached, the file is then scanned further to determine if there is any content that could be deemed potentially harmful (macros for example). If the file does not contain any content of this nature, it does not waste resources by uploading the file. I was able to test this using an Excel file with an embedded macro to ensure that uploads are indeed occurring when needed.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide