Brisco1165
Level 1
Level 1
Member since ‎03-25-2009
‎04-08-2019

User Statistics

  • 11 Posts
  • 0 Solutions
  • 10 Helpful votes Given
  • 5 Helpful votes Received
Recent Badges
1 Helpful Vote
5 Replies

User Activity

I have a hash for a file. I have blacklisted it under Application Blocking. I have it set to quarantine under Simple Detection. So why is it that my users can download it and execute it? It is marked malicious by AMP. VirusTotal has a ratio of 34/67 ...
I cannot block cmd.exe or wscript in my environment as a whole, but I would like to prevent MSWord and Excel from spawning them. There is no legitimate reason for Office products to kick of these. Can this be done through AMP?
I have an executable file, I used sha256deep to generate a hash. I confirmed that hash with an upload to VirusTotal as well as generating a hash through 7zip. I added the sha256 hash to my blocklist. Updated the policy on my endpoint. I was still abl...
Community Statistics
Member Since ‎03-25-2009 02:12 PM
Date Last Visited ‎04-08-2019 11:18 AM
Posts 11
Total Helpful Votes Received 5
Helpful Votes From
Helpful Votes Given To