cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1964
Views
0
Helpful
3
Replies

AMP | How to block malware in sourcefire

John
Level 1
Level 1

one of our appliance (non-cisco) detect the malware. we would like to know how can we block the malware to sourcefice.

please see attached sample malware.

3 Replies 3

David Janulik
Cisco Employee
Cisco Employee

The basic answer would be, the AMP detects malware based on signature details.The machine learning called Spero engine detect abnomalies in the system and finally threatgrid as dynamic analysis with power of API automatic sample submissions.

David

Cyber security escalation engineer

how do we determine if the sourcefire already block the malware?

in the dashboard > Analysis > events > Threat detected

This is displayed as day/week/All

To search up for particular malware, you need to know its SHA. Than you can use the filter under Analysis > Search.

David

Cyber security escalation engineer