11-08-2019 07:53 AM - last edited on 04-17-2020 01:27 PM by Monica Lluis
It appears there is no capability for Isolation on macOS, same with IOC Scans?
Is this true, and if it is, are those features being worked on?
Thanks.
11-08-2019 09:04 AM
The initial rollout of endpoint isolation is in the Windows connector. There are plans to extend this to the macOS and Linux connectors, but no precise dates that I can share at this point.
The Windows-specific Endpoint IOC scan feature has been there for a long time. There's some work under way (see the current open beta of Orbital Advanced Search for example) to add capabilities here, and again it's likely that this will show up for Windows first, and the other OS connectors to follow at a later point.
The prioritization is mainly a matter of Windows still being the leading target of attacks, as well as the largest chunk of the AMP connector installed base, so that's where the need is generally most acute.
11-08-2019 09:14 AM
Are you saying that Cisco has a single A4E software development team across all the desktop platforms (Windows\Linux\MacOS), and that they only advance one connector at a time?
11-10-2019 12:26 AM
The deployment of windows version is most advanced than others versions (macOS and Linux) because is the platform priority.
04-17-2020 03:06 PM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide