02-09-2021 09:10 AM
Dear community,
we have recently noticed several false positives on our IPS based on Firepower Managment Center, in particular signatures:
MALWARE-OTHER Win.Trojan.FANCYBEAR variant binary download attempt (1:56933:1) |
MALWARE-OTHER Win.Malware.Ursu-9821797-0 download attempt (1:56912:1) |
both of them seems to have legit traffic to Adobe.com or Eset.com. Why are detected as malware? Is there some additional tuning to do on our side?
Any ideas are welcome. Thank you!
R
02-09-2021 10:02 PM
02-10-2021 06:17 AM
Hello Mohammed,
we don't have SSL ispection for legal reasons. The idea to create a whitelist make sense and we can try to implement. I guess this is part of the URL filtering in the policy.
R
02-10-2021 06:53 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide