cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1088
Views
5
Helpful
2
Replies

Sourcefire Petya Ransomeware

ccg-security
Level 1
Level 1

Hi Cisco Support!

May we know if Sourcefire can now block the latest trends Petya Ransomeware? What is the latest VDB/signature update on IPS?

Thanks!

1 Accepted Solution
2 Replies 2

Marvin Rhoads
Hall of Fame
Hall of Fame

As noted in the TALOS blog Leo linked - yes NGFW/NGIPS will prevent the compromise (assuming it is setup correctly).

The same Snort Rule Update (released back in April) that covered Microsoft's MS17-010 blocks the CnC traffic.

The incoming infection can be blocked by AMP if you have it licensed and a file protection policy in place.

Review Cisco Networking for a $25 gift card