02-08-2022 07:16 AM
Hello,
We would like to distribute Secure Endpoint to other devices that are considered BYOD in our organization.
The issue of privacy concerns popped up, and we need to reassure the end-user of a private device, that Secure Endpoint cannot see files or folders on the device.
Solved! Go to Solution.
02-09-2022 10:48 AM - edited 02-09-2022 10:54 AM
That is partially correct. There are various methods for files to be pulled into the File Repository. The most common is "Automatic Analysis" which is limited to PE files. However other file types can end up in the File Repository from a request by the user in the Cisco Secure Endpoint console or via an "Automated Action". If the "Submit to Secure Malware Analytics upon Detection" automated action is enabled, it will put the detected file into the File Repository and send it to Cisco Secure Malware Analytics for analysis. Depending on your privacy setting for submission by Cisco Secure Endpoint to Secure Malware Analytics, the analysis results could be available to the "public".
There is the potential for bleeding over user data into the various Cisco Security products.Automated Action and User request for .doc* files
02-10-2022 01:36 AM
Every Sample submitted to Cisco Secure Malware Analytics gets tagged:
•Public –Sample will be visible globally (each user can access all the details of the report)
•Private –Sample is only visible to the submitting Organization
Automated Submissions from an AMP-Enabled Integration are always marked private
02-08-2022 09:07 AM
02-08-2022 09:14 AM
02-08-2022 10:00 AM
02-09-2022 10:10 AM
BTW, just wanted to mention... even you can query the endpoint and looking for files with Orbital, you cannot view the content of a file...
Regarding file uploads, Secure Endpoint support PEs only, so Text files or documents will not be uploaded to the File Repository.
Greetings, Thorsten
02-09-2022 10:48 AM - edited 02-09-2022 10:54 AM
That is partially correct. There are various methods for files to be pulled into the File Repository. The most common is "Automatic Analysis" which is limited to PE files. However other file types can end up in the File Repository from a request by the user in the Cisco Secure Endpoint console or via an "Automated Action". If the "Submit to Secure Malware Analytics upon Detection" automated action is enabled, it will put the detected file into the File Repository and send it to Cisco Secure Malware Analytics for analysis. Depending on your privacy setting for submission by Cisco Secure Endpoint to Secure Malware Analytics, the analysis results could be available to the "public".
There is the potential for bleeding over user data into the various Cisco Security products.Automated Action and User request for .doc* files
02-09-2022 08:44 PM
02-10-2022 01:36 AM
Every Sample submitted to Cisco Secure Malware Analytics gets tagged:
•Public –Sample will be visible globally (each user can access all the details of the report)
•Private –Sample is only visible to the submitting Organization
Automated Submissions from an AMP-Enabled Integration are always marked private
02-10-2022 01:40 AM
Thank you very much @Enrico Werner.
That really helps us with privacy and issues related to possible "info bleed."
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide