06-27-2017 08:50 PM - edited 03-10-2019 06:52 AM
Hi Cisco Support!
May we know if Sourcefire can now block the latest trends Petya Ransomeware? What is the latest VDB/signature update on IPS?
Thanks!
Solved! Go to Solution.
06-27-2017 10:39 PM
06-27-2017 10:39 PM
06-28-2017 03:31 AM
As noted in the TALOS blog Leo linked - yes NGFW/NGIPS will prevent the compromise (assuming it is setup correctly).
The same Snort Rule Update (released back in April) that covered Microsoft's MS17-010 blocks the CnC traffic.
The incoming infection can be blocked by AMP if you have it licensed and a file protection policy in place.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide