04-13-2023 12:13 PM
Hello everyone, 1st post here, we have been receiving a lot of alerts regarding firefox, see #2. Also I would like to know if #1 is a false positive,
Thanks for your help
Secure Endpoint found a total of 1 events matching your subscription named Indications_of_compromised since 2023-04-13 13:25:47 UTC.
2.
04-13-2023 12:20 PM
04-13-2023 01:37 PM
Thanks, anyone know anything about the firefox detection? All our end points flagged firefox and it's currently blocked by AMP.
04-13-2023 01:50 PM
The Firefox SHA-256 (5b2abf9947a12ff9cc3765e48d875d97752193fcbc5e2b89fdb3e138c3232568) is not related to the FP event from today.
Although this is an Exploit Prevention event, it is probably being generated because a 3rd party acting with Firefox and generating an unexpected behavior.
I suggest opening a TAC case to properly investigate. Our Cisco TAC team is ready to assist with the investigation.
--
Pedro M.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide