12-14-2021 09:25 AM
My organization has Cisco Amp for endpoint protection. The question we have is whether Amp scans for rootkits? We are also seeing a very high number of executable files show up as potential threats. Does Amp flag all ".exe" files as threats? Excel spreadsheets and system files are also showing up as potential threats. Does Amp flag all .xlsx files and system files as potential threats as well?
12-14-2021 10:15 AM
Hello @kristina.robinson ,
so let me try to answer your questions step-by-step
So finally, Secure Endpoint does not mark executable code or office documents as threats. Especially system files, as we use the guardrails to prevent the system from false/positives. I would suggest to open a TAC case so someone takes a deeper look into your environment. Based on your description I cannot provide any reliable statement what is going on on your endpoint.
Greetings,
Thorsten
12-14-2021 11:18 AM
Hi!
So are you saying that when I run full scans in Amp, it is automatically checking for rootkits as well or is there a separate scan to run for rootkits?
12-15-2021 12:18 AM
Hello @kristina.robinson ,
looks like there is an issue in the Console UI. So you can start a Rootkit scan on the endpoint, but not remotely from the console. You may check with TAC to get this solved.
Greetings,
Thorsten
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide