12-12-2021 04:39 AM
I use FMC Malware Policy but I have found from Network File Trajectory time 2021-12-10 07:26:11 is malware block, but in 2021-12-10 07:26:13 change to cloud lookup.
My FMC Malware Policy is what happened??
I search File Event show message : Retrospective Event, Fri Dec 10 01:12:19 2021(UTC), Old Disp: Neutral, New Disp:Malware, Threat Name:W32.FECA1C7AFE-100.SBX.TG;
I don’t understand the meaning of this message?
This is my Malware policy settings.
I settings two policy, the one is block Malware select all file type and the one policy Malware Cloud Lookup and select all file type.
12-13-2021 01:27 PM
It is hard to say as more info will be required. It is possible that the cached disposition for the particular file timed out and a new cloud lookup took place. I say this as I see, in your screenshot (on the top left), that the current disposition for this files is "unknown" Did you start seeing blocks after the cloud lookup?
Thank you for rating helpful posts!
12-19-2021 06:46 PM
I saw the cloud lookup after blocking.
Blocking occurs at 11 seconds, and cloud search occurs at 13 seconds.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide