06-17-2020 01:52 AM
I am trying to use AMSI from Windows 10 machine which has Cisco AMP for Endpoints installed. I am using C# code to access AMSI. AMSI fails to invoke Cisco AMP for endpoints AMSI provider. With little or no documentation there isn't a specific root cause that I could find. Though I do have some clue in one of the event log which reads like "Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\Windows Defender\MpCmdRun.exe) attempted to load \Device\HarddiskVolume4\Program Files\Cisco\AMP\scriptid\damsicom64.dll that did not meet the Microsoft signing level requirements." I assume damsicom64.dll is the Cisco AMP AMSI provider. Thought of seeking help here in the community to see if anyone has faced same issue and got some soltion for same ?
06-17-2020 02:26 AM
- Make sure that this is not due to an installed Anti-Virus solution (turn off temporarily and try again).
M.
06-17-2020 02:29 AM
11-10-2021 06:40 AM
Did you resolve this issue? I would like to know the details
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide