Endpoint Security

cancel
Showing results for 
Search instead for 
Did you mean: 
cancel

Cisco CyberSecurity

Forum Posts

Hi Team, We have an ASA5506 with Firepower managed by a FMC v6 running a PoC with a customer. We are adding in this project Cisco AMP for Endpoints due customer is interested to test the solution and see how is the integration of these two solutions....

Hi all;   One of the customer has asked if Cisco AMP product does it consider a shutdown and then power back on to be the same as a restart?   The reason of this questions is because there have been situations where after the connector upgrade the C...

eblandon by Cisco Employee
  • 4173 Views
  • 2 replies
  • 0 Helpful votes

Hello All, One of our SourceFire device has a Malware license and recently we enabled Malware blocking. We created a File policy with the action Block Malware with reset. From the Malware events, I can see the action as Cloud Lookup Timeout which ma...

Hello,we've found marvelous Talos work done on CCleaner, again respect for State of Art discovery - (no irony - best part of AMP solution).As an output, we got ClamAV signatures to detect this threat, all you need is to scan your infrastructure or wa...

natolin by Level 1
  • 2718 Views
  • 1 replies
  • 10 Helpful votes

Hi,please be aware that AMP "potential ransomware" email notifications does NOT work properly.We've tested it with the most obvious wannacry samples. Threat was detected as ransomware and quarantined but notifications are not send. We've opened TAC, ...

natolin by Level 1
  • 1888 Views
  • 1 replies
  • 0 Helpful votes