cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1062
Views
15
Helpful
4
Replies

Firesight | block wireshark .exe

John
Level 1
Level 1

We would like to know how to block wireshark .exe in firesight. 

4 Replies 4

Jetsy Mathew
Cisco Employee
Cisco Employee

Hello John

If you have malware license using file policy under policies 》 access control 》 File Policy , you can block the .exe extension.Do you want block only for wireshark.exe or all other .exe extension files ? 

Rate if post helps you

Regards

Jetsy

Hello Jetsy,

We want to block all installer of sniffing tool, like wireshark.exe.

Hello John, 

When the ASA FirePOWER module / Firepower devices detects an eligible file, the ASA FirePOWER module / Firepower devices then performs amalware cloud lookupusing the file’s SHA-256 hash value. Based on these results, the Cisco cloud returns a file disposition to the ASA FirePOWER module.

If a file has a disposition in the cloud that you know to be incorrect, you can add the file’s SHA-256 value to a file list:

  • To treat a file as if the cloud assigned a clean disposition, add the file to the clean list.
  • To treat a file as if the cloud assigned a malware disposition, add the file to the custom detection list.

If the system detects a file’s SHA-256 value on a file list, it takes the appropriate action without performing a malware lookup or checking the file disposition.

In order to block wireshark and other similar tools, please browse to 

FMC >> Objects >> Objects Management >> File List >> Custom Detection List  >> "Edit using the pencil icon" >> "Choose Calculate SHA in drop-down" >> Browse and Select file types for this list (For example, Wireshark EXEs, DMGs, etc)

Hope this helps.

Regards,

Pujita

Rate if this helps.

You may need to list all types of sniffing tools files and create their malware detection signature, including wireshark, nmap, and other types and add them to the malware detection policy.  Cisco TAC can assist or you can load your own. Happy tunning.

Review Cisco Networking for a $25 gift card