cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1733
Views
0
Helpful
2
Replies

AMP Endpoint scanning its own quarantine????

Steve Bellan
Level 1
Level 1

I thought by default it did not scan its own quarantine folder. We are getting a lot of alerts from this. No big deal if we have to add to exclusions manually, just making sure not missing something. 

2 Replies 2

nspasov
Cisco Employee
Cisco Employee

Can you:

1. Post the exact path that the alert is coming from

2. Screenshot of the notification

 

Thank you for rating helpful posts!

Matthew Franks
Cisco Employee
Cisco Employee

Steve,

 

This could happen if you've created a new policy and didn't include the default exclusion set.  By default, AMP does not scan its own directories, but it could if those exclusions were removed.

 

-Matt