A company recently discovered an attack propagating throughout their Windows network via a file named abc123456789xyz.exe. The malicious file was uploaded to a Simple Custom Detection list in the AMP for Endpoints Portal and the currently applied policy for the Windows clients was updated to reference the detection list. Verification testing scans on known infected systems shows that AMP for Endpoints is not detecting the presence of this file as an indicator of compromise. What must be performed to ensure detection of the malicious file?
DWizard
Highly Voted 1 year, 5 months agoDemon_Queen_Velverosa
Most Recent 2 months, 2 weeks agoDemon_Queen_Velverosa
2 months, 2 weeks agoDemon_Queen_Velverosa
2 months, 2 weeks agoluismg
2 months, 4 weeks agoDemon_Queen_Velverosa
2 months, 2 weeks agoTthurston1
6 months, 3 weeks ago4pelos
9 months, 2 weeks agoCCNPWILL
1 year, 1 month agounclemonkeyboy
1 year, 6 months agoCCNPWILL
1 year, 1 month ago