Cisco Secure Endpoint malicious file detected on multiple hosts
Set up the cisco-secure-endpoint integration.
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、
お気軽にご連絡ください。
Goal
Detect when a malicious file is found on multiple hosts.
Strategy
This rule monitors Cisco Secure Endpoint logs for detecting when a malicious file is found on multiple hosts.
Triage and response
- Investigate the file,
{{@event.file.file_name}}
, to determine if the file is malicious. - Investigate host(s) (
{{@event.computer.hostname}}
) in which the malicious file has been detected. - Analyze the file activity pattern for the potential attack.
- Implement immediate measures to block or limit the impact of the suspicious activity, if confirmed as a threat.
- Follow company procedures for handling malicious files, including isolating the endpoint, running antivirus/antimalware scans, analyzing logs, and updating security policies.