Resolved! CSIDL_BASEDIR Path Exclusion?
What does the CSIDL_BASEDIR path exclusion do? I keep looking online for documentation and can't seem to find anything that gives a clear answer.
What does the CSIDL_BASEDIR path exclusion do? I keep looking online for documentation and can't seem to find anything that gives a clear answer.
Today there are multiples detections related to Winrar.exe. It looks like a false positive, but it´s weird, Is there a reason for this? The hash is e97e8fb9fdf2df5d8d5a4efcbd6d2eee42900c2de44f34f93fa25d8f84b80e80.
Hello,i have cisco sf350,sf200 and sf220 in my organization,sf200 and 350 works good with port security (there are option "secure permanent" which saves source mac and blocks if u plug in another mac but with sf220 there are only dynamic lock which o...
Boa tarde pessoal, como vão? Pessoal estou deixando na TV do escritorio a tela com o AMP aberto. Mas de tempos em tempos ele desloga e pede credenciais de novo. Como posso resolver essa questão?
Good morning, I sent the connector to update to the latest version (8.2.1.21612) and after waiting a few hours I see that I have 300 devices in the inbox that report the same event, which is "Suspicious smss.exe Parent Process". Could the new version...
Hello everyone. I am looking for a way to make Cisco Secure Endpoint to work with and send logs in real time to Google Chronicle SIEM.Can you please provide some instruction, if there is any? Thank you in advance!
We are having an issue where AMP has given multiple computers the same GUID ID. We have tried deleting the local.xml and local.xml.old files and restarting the service with no luck. I just saw that the v3 of the API has the ability to uninstall the c...
I am trying to stop the Secure Endpoint service to do testing and I am not able to do so.Following these documents:https://www.cisco.com/c/en/us/support/docs/security/amp-endpoints/213690-amp-for-endpoint-command-line-switches.htmlhttps://www.cisco.c...
Hi Everyone -Good day! I am new with CSE and part of my task is to upload IOCs using XML files from CISO. I got an error when I uploaded the file from CISO.The Endpoint IOC is not currently able to be validated according to the Cisco IOC specifiation...
Is there a way to safelist or create an exclusion for this benign powershell command without safelisting cmd.exe or powerhell.exe - just the actual Command parameter? These events are classified as "Command Obfuscation With Symbols" compromises and ...
Good morning everyone, I have a problem that on some machines the Service Status is in Stopped.Would anyone know what might be causing this?
It appears there's no "help" option in the training labs. I don't think the lab is complete as I'm unable to complete all functions in the lab. In particular, the environment module we import into our Python script doesn't have anything inside of it ...
Hi , can any one please help me out to receive daily email alerts of complete detection. I am using SourceFire v5.3 console and have tried creating a filter in "Analysis --> Detections/Quarantine" then subscribing a daily detections email alert, howe...
Hey all - I have numerous endpoints that are showing as not being seen in xx amount of days in the portal. However if I remote into these endpoints and check the secure endpoint application it shows as connected, pull down updates and has even update...
Good day all! From time to time, I find that there are several of our machines that have their service stopped with Secure Endpoint. I haven't found what has been stopping it, but has anyone seen this and know what has been causing this? And is there...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide
Subject | Author | Posted |
---|---|---|
02-24-2025 10:06 AM | ||
01-20-2025 06:30 AM | ||
12-18-2024 01:13 PM | ||
12-04-2024 09:36 AM | ||
11-05-2024 01:09 PM |