cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2128
Views
25
Helpful
3
Replies

Cisco Endpoint Security Question

IamSamSaul
Level 1
Level 1

Hello,

Is there a way to check what happened to the malicious file when Cisco Endpoint Security detects a threat and generate an even.

 

When I enter the Sha-256 hash I can see other information but not what happened? For example: Threat detected and file was quarantined or file deleted.

 

Thanks & Regards,

Sam

2 Accepted Solutions

Accepted Solutions

That should appear in the dashboard, events for the endpoint, the device trajectory...

View solution in original post

Troja007
Cisco Employee
Cisco Employee

Hello @IamSamSaul, as @Ken Stieers already explained.
When checking the Event, you just need to open the Device Trajectory. In the example from the attached screenshot, i also filtered for the SHA256 hash of the malicious file.
Greetings,
Thorsten

DeviceTrajectoryMalicious File.png

View solution in original post

3 Replies 3

That should appear in the dashboard, events for the endpoint, the device trajectory...

Troja007
Cisco Employee
Cisco Employee

Hello @IamSamSaul, as @Ken Stieers already explained.
When checking the Event, you just need to open the Device Trajectory. In the example from the attached screenshot, i also filtered for the SHA256 hash of the malicious file.
Greetings,
Thorsten

DeviceTrajectoryMalicious File.png

IamSamSaul
Level 1
Level 1

Thanks both Ken and Thorsten. 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: