Hi all there,
I need your help, I tried to connect in cortex Cisco AMP, but need to have "AMP for Endpoints Simple Custom Detection GUID".
Can anyone help me how can I get. I created simple and assigned it to my police, but GUID for this group nowhere appeared.
also, I found steps here: https://ciscosecurity-amp-00-integration-workflows.readthedocs-hosted.com/en/latest/amp/response_actions.html#get-scd-list-guids but it doesn't works.