1397
Views
0
Helpful
0
Replies
AMP for Endpoints- Unknown detection

Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
11-09-2018 01:12 AM - edited 02-21-2020 08:27 AM
We have had a detection on one of our customers network which is named UNKNOWN and has a SHA of all 0's, it has been quarantined and is creating tickets in the AMP inbox, but there is no way to tell what this is.
Has anyone seen this before and is there any way of looking into this without a diagnostics file being obtained and sent to Cisco TAC?
Thank you,
Molly
Labels:
0 Replies 0
