cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1547
Views
25
Helpful
5
Replies

Indication of Compromise Alerts Flooding my Outlook Inbox

richard.wing
Level 1
Level 1

Event Type: Cloud IOC

File: powershell.exe

File path: C:/Windows/system32/WindowsPowerShell/v1.0/powershell.exe

I get this alert for all CyberArk EPM Clients where the CyberArk EndPoint Management (EPM) Agent uses PowerShell scripts to implement CyberArk EPM Policies. It's blocking the C:\Program Files\CyberArk\Endpoint Privilege Manager\Agent\PASAgent\SFDP.dll from running. How to I stop Cisco Secure Endpoint from blocking it?

5 Replies 5

You can mute it by opening one of the alerts and clicking on the bell.
Exclusions might work, but the Cloud IOCs are based on behavior that it looks at after the fact.

Troja007
Cisco Employee
Cisco Employee

Hello @richard.wing ,
we are aware of this issue and are working on a solution. Hopefully we will provide Cloud IOC exclusions soon. Today I cannot share any ETA for this, but you may ping your Cisco representative for details.

Until we provide this feature, please open a TAC case, so we can add an appropriate exclusion to the backend detection engine.
Greetings, Thorsten

 

Deleted - mistaken dates

At the moment there is no way to create exclusions for Cloud IOC events. As mentioned by others the only thing you can do is create a TAC Case and provide them with as much information about the event as possible, e.g. filename, SHA-256 value, command line arguments etc. so they can reach out the development team to tune the events which happen globally... Yes, you heard correct. Cisco is unable to provide any kind of tuning or exclusion specifically for your organization, whatever they do back-end affects all Secure Endpoint customers globally.

 

I have a customer that develops powershell scripts that are run on their servers with Secure Endpoint installed. Almost any type of script is triggering a new Cloud IOC even though it's relatively harmless, one of the scripts would collect health information from the server.. I think we're on TAC Case number three for having Cisco tune these Cloud IOCs which seems pointless as they keep triggering a new event every time they create a new script. It typically takes Cisco weeks to do and all the cases we have opened always receive an initial response from the engineer saying exclusions are not possible. Not sure if they just can't be bothered and think they can get the case closed faster or maybe they simply don't now.. 

Best Regards
Nicolai Borchorst
CCIE Security #65775

Hello @Nicolai Borchorst ,
we are already working on this feature. Today I do not have an ETA for you to share here. You may ping your Cisco representative for details.

Greetings, Thorsten