Endpoint Security

cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Cisco CyberSecurity

Forum Posts

We have 1500 AMP for Endpoints licenses - I just watched a video on deploying them - from what I saw I would need each pc to go to https://console.amp.sourcefire.com portal page and download these individually. 1 - How would I get a login for the so...

moody by Level 1
  • 80110 Views
  • 40 replies
  • 0 Helpful votes

Hi everyone,Cisco AMP found different malicious files, I saw 2 different dispositions on Cisco AMP:Disposition: MaliciousDisposition: BlocklistedBoth files quarantined but can someone explain what is the difference between blocklisted and malicious d...

tobbyf by Level 1
  • 1513 Views
  • 4 replies
  • 0 Helpful votes

For a long time I received many alerts about the Powershell being indentified as Malware, when a retrospective Malware alert was received making that file as Clean.Common detecion: W32.PowershellEncodedBuffer.iocDid anyone else see this same behavior...

Good morning. I understand that integration with Talos Cloud is necessary to properly use malware detection through FMC and FTD. How can I apply it in a closed network? SRU or Geo information can be manually imported, and I wonder if the FMC also has...

Translator by Community Manager
  • 564 Views
  • 2 replies
  • 0 Helpful votes

Hey everyone, Just wondering if anyone knows why a user would get a Event 5400 Authentication failed (Failure Reason is 22056 Subnet not found in the applicable identity store(s).  The laptop has just gone through a successful authentication and swit...