Like the title suggests, I am slowly, but surely working on responding to alerts, and one that I am working on today is AMSI. We are having an audit and AMSI is alerting of violations on our network but we are in observe mode.
I guess my question is if this was live, what would be best practices to combat this?
What product is sending the alerts?
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
ePolicy. I have a automatic response to malware detected and not handled.
EPO only alerts on the event, but it is ens or vse that is sending the event and they would be the ones to ask how to handle any live events. I will move this over to them.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Thank you!
If you have EDR, you will have more visibility into what is happening. Otherwise, you really need script block logging enabled on your endpoints, and then to review those logs to see what ran.
Dave
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA