Endpoint Security

cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Cisco CyberSecurity

Forum Posts

Hi everyone,Cisco AMP found different malicious files, I saw 2 different dispositions on Cisco AMP:Disposition: MaliciousDisposition: BlocklistedBoth files quarantined but can someone explain what is the difference between blocklisted and malicious d...

tobbyf by Community Member
  • 3392 Views
  • 4 replies
  • 0 Helpful votes

For a long time I received many alerts about the Powershell being indentified as Malware, when a retrospective Malware alert was received making that file as Clean.Common detecion: W32.PowershellEncodedBuffer.iocDid anyone else see this same behavior...

Hey everyone, Just wondering if anyone knows why a user would get a Event 5400 Authentication failed (Failure Reason is 22056 Subnet not found in the applicable identity store(s).  The laptop has just gone through a successful authentication and swit...

So one would think this is a basic requirement for a MDM solution; install an app, update said app - done and dusted.Sadly I seem not to be able to do this of late.I force a refresh of VPP apps via the apps page; I choose an app and select "Out of da...

image.png image.png image.png
Richard_W by Level 5
  • 6757 Views
  • 5 replies
  • 0 Helpful votes

Resolved! Spero and ETHOS

Hello, I am just getting familiar with Secure Endpoint and would like to know more about Spero and Ethos engine. I could not find DETAILED information about how these engines work and what they do. Would be grateful if someone provides documentation....

llomjaria by Level 2
  • 6461 Views
  • 3 replies
  • 0 Helpful votes

Good day all! We've come across a few incidents where we would initiate a scan(full or flash) on a machine from the console and the events of the scan starting and finishing would show up over an hour after those events actually happened. Is this com...

mandrews by Level 1
  • 564 Views
  • 0 replies
  • 0 Helpful votes