cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2690
Views
0
Helpful
1
Replies

File dispositions

cglz
Level 1
Level 1

Hi,

How can I have the following:

Full scan started by the scheduler.

Scan completed successfully.

Found 10 detections, 0 suspicious files and 0 hidden files.

Scan time 6 hours.

Scanned 1244779 files, 289367 directories and 109 processes.

Engines used: SHA, ETHOS, SPERO, Tetra.

However, there are no malicious events in the file/device trajectory, but it found 10 detections.

I do understand that often times the dispositions of, some files, can be unknown therefore the item is flagged until the virustotal engine can provide an accurate disposition of the file; however, over the last several days, I am seeing this over a number systems.

Is it simply a matter of lag time on the part of getting the disposition?

Please advise.

Best

1 Reply 1

E.L. Howard
Cisco Employee
Cisco Employee

Hello - can you post a screenshot [sanitized if necessary] of the your DT view?

Also, as an FYI - we do not have a VirusTotal engine. We do show users what VirusTotal may report against a file though.

ELH

--
ELH