cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2249
Views
25
Helpful
3
Replies

Cisco Endpoint Security Question

IamSamSaul
Level 1
Level 1

Hello,

Is there a way to check what happened to the malicious file when Cisco Endpoint Security detects a threat and generate an even.

 

When I enter the Sha-256 hash I can see other information but not what happened? For example: Threat detected and file was quarantined or file deleted.

 

Thanks & Regards,

Sam

2 Accepted Solutions

Accepted Solutions

That should appear in the dashboard, events for the endpoint, the device trajectory...

View solution in original post

Troja007
Cisco Employee
Cisco Employee

Hello @IamSamSaul, as @Ken Stieers already explained.
When checking the Event, you just need to open the Device Trajectory. In the example from the attached screenshot, i also filtered for the SHA256 hash of the malicious file.
Greetings,
Thorsten

DeviceTrajectoryMalicious File.png

View solution in original post

3 Replies 3

That should appear in the dashboard, events for the endpoint, the device trajectory...

Troja007
Cisco Employee
Cisco Employee

Hello @IamSamSaul, as @Ken Stieers already explained.
When checking the Event, you just need to open the Device Trajectory. In the example from the attached screenshot, i also filtered for the SHA256 hash of the malicious file.
Greetings,
Thorsten

DeviceTrajectoryMalicious File.png

IamSamSaul
Level 1
Level 1

Thanks both Ken and Thorsten.