Endpoint Security

cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Cisco CyberSecurity

Forum Posts

I am using pda through cisco wireless. and, apWhile replacing it with 9120, the authentication method was changed to 802.1x. According to the customer, the service has been unstable since the change, and looking at the log of the pda,intermittentlyCo...

CCC3 by Level 5
  • 618 Views
  • 0 replies
  • 0 Helpful votes

Hello everyone,I have created multiple workflows to alert on different types of events and now I am looking for a possibility to initiate a full scan via SecureX workflow. I have run through API documentation (https://api-docs.amp.cisco.com/api_resou...

bisskar by Community Member
  • 980 Views
  • 1 replies
  • 0 Helpful votes

We have 1500 AMP for Endpoints licenses - I just watched a video on deploying them - from what I saw I would need each pc to go to https://console.amp.sourcefire.com portal page and download these individually. 1 - How would I get a login for the so...

moody by Level 2
  • 88279 Views
  • 40 replies
  • 0 Helpful votes

Hi everyone,Cisco AMP found different malicious files, I saw 2 different dispositions on Cisco AMP:Disposition: MaliciousDisposition: BlocklistedBoth files quarantined but can someone explain what is the difference between blocklisted and malicious d...

tobbyf by Community Member
  • 2990 Views
  • 4 replies
  • 0 Helpful votes

For a long time I received many alerts about the Powershell being indentified as Malware, when a retrospective Malware alert was received making that file as Clean.Common detecion: W32.PowershellEncodedBuffer.iocDid anyone else see this same behavior...