12-16-2018 08:49 PM - edited 02-20-2020 09:07 PM
Hi Sir:
My environment is below:
1.AMP Endpoint for MAC and windows
2. Private Cloud on Intranet
When I find one suspect file (I think it's malware file.)but AMP endpoint can't analyze it. It think it's normally. What can I do for this file ? Can we send it to AMP Threat Grid by Private Cloud ? or provide me any recommendation ? Thanks
01-28-2019 02:39 AM
Hello Peter!
With Threat Grid you can analyze the suspect file, and use the AMP to block the file or the computer.
01-28-2019 03:02 AM
If the file gets TG score >95, AMP will retrospectively quarantine it.
01-28-2019 08:52 AM
Send it to Threat Grid for more investigation, or copy SHA-256 and paste it in Cisco Visibility, All integrated devices (WSA, ESA, CES, FMC, etc.) including AMP for Endpoints are entitled to 200 samples per day regardless of the number of devices and this is applicable for the license bought after 12/1/2017.
01-29-2019 06:47 AM
Hi MajidShirzadeh:
If my client had bought the Threat Grid. We can upload any file to it and analyze it. Right ?
(Because I had tried to upload the file to public cloud . It must approve by Cisco and I will receive the mail. It will tell me it ok or not. Then I can find the file on the File analyze.If my client buy the Thread Guid application. We can control the file upload it or not right ?)
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide