07-05-2022 02:28 PM
So, we have some files sent to file analysis that come back as no malware detected, but even on the analysis it comes back as very high threat.
Here is the file in question:
So, I'm guessing it's since the default threat level is 95 and this scored an 85. My question is what do people set this to not be to harsh and stop phishing
Thanks,
Solved! Go to Solution.
07-06-2022 12:57 AM
While TAC do not generally recommend reducing the score below default (90), I have seen customers playing around between 80 - 85. But this was brought up to TAC since some of those were false positive detections due to low threshold score than what AMP provides as a final verdict.
This is always a bit of hit and miss. You can monitor them for a while to understand the overall symptoms. But be careful about setting the action to drop since you may end up loosing genuine emails.
07-06-2022 12:57 AM
While TAC do not generally recommend reducing the score below default (90), I have seen customers playing around between 80 - 85. But this was brought up to TAC since some of those were false positive detections due to low threshold score than what AMP provides as a final verdict.
This is always a bit of hit and miss. You can monitor them for a while to understand the overall symptoms. But be careful about setting the action to drop since you may end up loosing genuine emails.
07-06-2022 06:14 AM
Yeah, looking at others, I see some legit hitting around a score of 81. We are going to try 85 and see what happens.
On a side note, we have 3 ESAs all same model and code version. 1 has a default of 95, the other 2 had a default of 90.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide