12-14-2018 08:38 AM - edited 03-12-2019 07:10 AM
Hi All,
Can anyone please confirm if Dynamic Analysis with either Block Malware or Malware Cloud Lookup sends the full file to the AMP cloud or only the SHA value? If it sends the full file, does the AMP cloud delete the file after analysis? Are there generally any concerns with sending full file to AMP for analysis? I have a customer that has queried this and is concerned about sensitive files from being sent out of the network
Thank you
12-14-2018 09:48 AM - edited 12-14-2018 10:12 AM
SHA value goes to SPERO, ETHOS engine
Spero Analysis for MSEXE
Dynamic Analysis: This option sends files that match the rule to the "sandbox" for further analysis. This produces a file threat score and a file report (usually within 20 minutes).
Reset Connection
Store Files (By Disposition) Malware, Unknown, Clean, or Custom
Malware Cloud Lookup: Allows you to log the malware disposition of files that are traversing your network based on a cloud lookup, while still allowing their transmission
Block Malware: Allows you to calculate the SHA-256 hash value of specific file types, then use a cloud lookup process to first determine if files that are traversing your network contain malware, and then block files that represent threats
12-14-2018 10:19 AM
Hi
Thanks for the response. What happens if the file/SHA value is unknown, is the complete file then sent to the sand box for further analysis?
12-14-2018 10:34 AM - edited 12-14-2018 10:36 AM
12-16-2018 05:28 AM
For customers with a high degree of sensitivity you can run AMP Private Cloud and ThreatGrid all on-premises. In that scenario no customer file ever leaves the environment.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide