ā01-19-2016 10:19 PM - edited ā03-12-2019 05:52 AM
Hello,
Does the Firesight Manager send actual files to the malware lookup cloud for sand box scanning or only hashes. One of our management team raised a concern of sensitive files being sent to the cloud, perhaps if the cloud is hacked then such files can be leaked. Can someone elaborate on the cloud lookup process
All help is appreciated
Regards,
Moe Shea
ā01-20-2016 01:33 AM
You can have it both ways. First a hash is sent to the cloud. And if you configure it that way, the file can be sent to the cloud for inspection.
There is also the option to do a private cloud install for inspection. But that's quite expensive and not the way it's really designed to work.
ā01-20-2016 02:00 AM
Thanks Karsten for the reply,
Could you tell me where to make this selection, i.e. only send the hash and not the file, because in the action drop down menu I have the following selection,
=========
Detect Files
Block Files
Malware Cloud Lookup
Block Malware
=========
Regards,
Moe Shea
ā01-20-2016 02:31 AM
It's enabled directly below your mentioned options: "Dynamic Analysis".
ā01-20-2016 03:48 AM
Thanks Karsten for the feedback,
To reconfirm, if I select the Dynamic Analysis then the files will be submitted, otherwise no files will be submitted hence no fear of files being leaked, only hashes and exe (with Spero selected), right?
ā01-20-2016 03:59 AM
Nearly correct. Also if it's disabled in the File policy, an Admin could send a file manually to dynamic analysis. But for sure, that won't happen without manual action.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide