cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2425
Views
11
Helpful
7
Replies

How Cisco AMP Endpoint take action?

RoberSamir00332
Level 1
Level 1

Hi All;

 

i want to know how Cisco AMP Endpoint take action when it detect a Malware on the PC

 

Regards;

Rober

2 Accepted Solutions

Accepted Solutions

Troja007
Cisco Employee
Cisco Employee

Hello @RoberSamir00332,
there many different ways Cisco Secure Endpoint takes action on Malware.

  1. Starting with traditional File scanning, File scanning for Scripts (AMSI integration), Malware Grouping, Machine Learning, where the Endpoint quarantines a file and also stops a running process.
  2. There are other engines, which are protecting the memory like ExPloit Prevention and System Process Protection. These engines protect against memory based attacks.
  3. Behavioral Protection Engine is the newes enhancement on the endpoint. It detects and blocks complex malicious behavior on the endpoint. The engines uses am expressive event pattern matching language designed by Cisco.
  4. Cloud IOCs: The endpoint sends file, network, process and command line activity to the backend. This data is processed back for 7 days. The result is a Cloud IOC or a retrospective detection.
  5. Based on Cloud IOCs, there are automated Post Infection Tasks available, like isolating the endpoint from the network.

Maybe useful, the screenshot compares the difference between a Cloud IOC from the Backend and a Behavioral Protecton Event.

CloudIOC vs BPE Detection.png

 

Greetings,
Thorsten

View solution in original post

Hello Ken,
TDM = Technical Decision Maker Presentation.
Cheers,
Thorsten

Troja007_0-1741207589023.png

 

View solution in original post

7 Replies 7

Troja007
Cisco Employee
Cisco Employee

Hello @RoberSamir00332,
there many different ways Cisco Secure Endpoint takes action on Malware.

  1. Starting with traditional File scanning, File scanning for Scripts (AMSI integration), Malware Grouping, Machine Learning, where the Endpoint quarantines a file and also stops a running process.
  2. There are other engines, which are protecting the memory like ExPloit Prevention and System Process Protection. These engines protect against memory based attacks.
  3. Behavioral Protection Engine is the newes enhancement on the endpoint. It detects and blocks complex malicious behavior on the endpoint. The engines uses am expressive event pattern matching language designed by Cisco.
  4. Cloud IOCs: The endpoint sends file, network, process and command line activity to the backend. This data is processed back for 7 days. The result is a Cloud IOC or a retrospective detection.
  5. Based on Cloud IOCs, there are automated Post Infection Tasks available, like isolating the endpoint from the network.

Maybe useful, the screenshot compares the difference between a Cloud IOC from the Backend and a Behavioral Protecton Event.

CloudIOC vs BPE Detection.png

 

Greetings,
Thorsten

A very interesting answer. thanks

Troja007
Cisco Employee
Cisco Employee

Hello all, the new TDM includes the drawing above and much more...

TDM ???

Hi Ken, I think Cisco Secure Endpoint "TDM" refers to the threat detection and management capabilities within the Cisco Secure Endpoint platform. Don't like acronyms either they change all the time 

Hello Ken,
TDM = Technical Decision Maker Presentation.
Cheers,
Thorsten

Troja007_0-1741207589023.png