05-03-2018 01:46 PM - edited 03-08-2019 05:47 PM
Hi,
We are seeing an issue where the default Cisco AMP exclusions for Outlook aren't enough because Outlook Temp is also under /private/var so it's scanning this location and we are getting inundated with Threat Detected notifications every time someone's Outlook receives an attachment. As guess my question is has anyone had success with excluding the /private/var Outlook Temp as well, this would have to be done with wildcards as the folder name is randomized.
--
Sean
Solved! Go to Solution.
05-03-2018 10:25 PM
Hello Sean
Do you have the MAC or Windows endpoint facing this issue ?
Just try the following if you are having a MAC workstation and let me know if this works. Compare the path with the one which you have.
Wildcard /private/var/folders/*/*/*/com.microsoft.*/Outlook Temp
Regards
Jetsy
05-03-2018 10:25 PM
Hello Sean
Do you have the MAC or Windows endpoint facing this issue ?
Just try the following if you are having a MAC workstation and let me know if this works. Compare the path with the one which you have.
Wildcard /private/var/folders/*/*/*/com.microsoft.*/Outlook Temp
Regards
Jetsy
05-04-2018 08:36 AM
Thank you so much Jetsy!
We have all MAC endpoints and the file paths we are currently excluding are:
Suggested by Cisco Support docs, so a follow up questions is can this be added to the defaults as I'd imagine anyone who manages MAC endpoints is going to have this same issue because Outlook is storing in the /private/var path as well.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide