03-03-2022 07:08 AM
Event Type: Cloud IOC
File: powershell.exe
File path: C:/Windows/system32/WindowsPowerShell/v1.0/powershell.exe
I get this alert for all CyberArk EPM Clients where the CyberArk EndPoint Management (EPM) Agent uses PowerShell scripts to implement CyberArk EPM Policies. It's blocking the C:\Program Files\CyberArk\Endpoint Privilege Manager\Agent\PASAgent\SFDP.dll from running. How to I stop Cisco Secure Endpoint from blocking it?
03-03-2022 07:43 AM
03-21-2022 05:59 AM
Hello @richard.wing ,
we are aware of this issue and are working on a solution. Hopefully we will provide Cloud IOC exclusions soon. Today I cannot share any ETA for this, but you may ping your Cisco representative for details.
Until we provide this feature, please open a TAC case, so we can add an appropriate exclusion to the backend detection engine.
Greetings, Thorsten
03-21-2022 10:19 AM - edited 03-21-2022 10:20 AM
Deleted - mistaken dates
03-22-2022 10:03 AM
At the moment there is no way to create exclusions for Cloud IOC events. As mentioned by others the only thing you can do is create a TAC Case and provide them with as much information about the event as possible, e.g. filename, SHA-256 value, command line arguments etc. so they can reach out the development team to tune the events which happen globally... Yes, you heard correct. Cisco is unable to provide any kind of tuning or exclusion specifically for your organization, whatever they do back-end affects all Secure Endpoint customers globally.
I have a customer that develops powershell scripts that are run on their servers with Secure Endpoint installed. Almost any type of script is triggering a new Cloud IOC even though it's relatively harmless, one of the scripts would collect health information from the server.. I think we're on TAC Case number three for having Cisco tune these Cloud IOCs which seems pointless as they keep triggering a new event every time they create a new script. It typically takes Cisco weeks to do and all the cases we have opened always receive an initial response from the engineer saying exclusions are not possible. Not sure if they just can't be bothered and think they can get the case closed faster or maybe they simply don't now..
03-24-2022 06:24 AM
Hello @Nicolai Borchorst ,
we are already working on this feature. Today I do not have an ETA for you to share here. You may ping your Cisco representative for details.
Greetings, Thorsten
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide