cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
8200
Views
0
Helpful
4
Replies

AMP for Endpoints and Windows Defender false positives

Hi all,

 

I have a freshly installed windows 10 pro with an AMP for Endpoints connector running in conjunction with Windows Defender. Windows Defender quickly started finding all kinds of "threats" in paths like

 

C:\Program Files\Cisco\AMP\clamav\0.99.2.35\temp\clamtmp\0005718b.tmp
C:\Program Files\Cisco\AMP\clamav\0.99.2.35\temp\clamtmp\clamav-61129689be88cab63e3e69f5866eb3c1.tmp\pdf45

 

I'm presuming that these are virus definitions, and the solution is to add C:\Program Files\Cisco\AMP\clamav to Windows Defender's ignore list.

 

  1. Can someone confirm that this is indeed what is happening and the correct solution?
  2. Defender quarantined about 8 files automatically; will this negatively affect AMP?

Thanks in advance,
Jack

2 Accepted Solutions

Accepted Solutions

Matthew Franks
Cisco Employee
Cisco Employee

Jack,

 

You are correct that these are signatures.  Without these, AMP won't be able to perform local file analysis.  If you're going to run Defender and AMP together, please exclude the AMP directories from Defender and Defender directories from AMP.

 

Thanks,

Matt

View solution in original post

The connector will check in every hour by default (can be set in the policy) to ensure the signatures are up to date.  At that point, it should download the missing files.

 

-Matt

View solution in original post

4 Replies 4

Matthew Franks
Cisco Employee
Cisco Employee

Jack,

 

You are correct that these are signatures.  Without these, AMP won't be able to perform local file analysis.  If you're going to run Defender and AMP together, please exclude the AMP directories from Defender and Defender directories from AMP.

 

Thanks,

Matt

Thanks! Will the already quarantined files be automatically fixed in AMP?

The connector will check in every hour by default (can be set in the policy) to ensure the signatures are up to date.  At that point, it should download the missing files.

 

-Matt

Awesome, thanks!