03-26-2021 08:03 AM
We recently had a new client get hit with the DarkSide Crypto Ransomware that came from inside their network. We found some vulnerabilities on their servers that the client had setup and ended them in this situation. My manager asked me to look into AMP to see if there are settings within AMP that might have protected their servers as well as their workstations.
I have some knowledge of AMP for Endpoints with setting up the basics on workstations. The clients we have are mostly smaller clients and are using AMP to protect workstations. The larger clients are either maintained by their internal IT departments and our mid-sized are maintained by our Cisco engineers.
Solved! Go to Solution.
03-26-2021 07:13 PM
Hi,
If you have AMP installed on those new clients and recommended engines running in the AMP policies, then AMP must have provided protections against the DarkSide Crypto Ransomware as Cisco TALOS already has detection against the same from last year.
Please search on the TALOS website for the given SHA-256 value for the Ransomware and you will be able to get the information on the detection as below:
https://talosintelligence.com/sha_searches
SHA-256: 9cee5522a7ca2bfca7cd3d9daba23e9a30deb6205f56c12045839075f7627297
Please refer to the attached screenshot.
Also, please refer to the below Deployment Strategy guide for the policy settings recommendations for your servers and workstations:
https://docs.amp.cisco.com/en/A4E/AMP%20for%20Endpoints%20Deployment%20Strategy.pdf
I hope the above helps!
Cheers,
Pratham
03-26-2021 08:40 AM
03-26-2021 07:13 PM
Hi,
If you have AMP installed on those new clients and recommended engines running in the AMP policies, then AMP must have provided protections against the DarkSide Crypto Ransomware as Cisco TALOS already has detection against the same from last year.
Please search on the TALOS website for the given SHA-256 value for the Ransomware and you will be able to get the information on the detection as below:
https://talosintelligence.com/sha_searches
SHA-256: 9cee5522a7ca2bfca7cd3d9daba23e9a30deb6205f56c12045839075f7627297
Please refer to the attached screenshot.
Also, please refer to the below Deployment Strategy guide for the policy settings recommendations for your servers and workstations:
https://docs.amp.cisco.com/en/A4E/AMP%20for%20Endpoints%20Deployment%20Strategy.pdf
I hope the above helps!
Cheers,
Pratham
03-31-2021 06:34 AM
Pratham,
Unfortunately this was a new client that was pulled into our data center and they did not have AMP installed. My management is looking to approach them with getting this purchased and installed on all of their servers and workstations, but needed additional information.
Thank you for the information and your time.
Joe
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide