Win10 & Server 2016 will provide an interface to scan for malicious scripts (ie Powershell)
When will Viruscan Enterprise or Endpoint Security 10 support this?
Solved! Go to Solution.
Hello,
AMSI is supported by McAfee Endpoint Security 10.6.
It's not planned with VirusScan Enterprise.
Regards,
Olivier
Thanks Cara, you solved my issue!
If anyone else is wondering, yes, McAfee can provide you with files that can be used to test that your AMSI is properly configured and that any alerts you have setup via automated responses are also triggered properly.
Thanks,
Adam
Hello,
AMSI is supported by McAfee Endpoint Security 10.6.
It's not planned with VirusScan Enterprise.
Regards,
Olivier
10.6 finall ist out. We migrated 4 of 35 smaller and 2 larger enterprise to 10.6. Internal in our development network where people have several Powershell scripts it already hit some false/Positive. If you have developer PC with a lot of tools, addons for different languages you may have to turn it off. Mainly when oyu update or install opensource tools with routines on Powershell on Windows 10.
At all around 15 developer clients and 2 (Two) false positive. One was from https://github.com/Maximus5/ConEmu/wiki/ConEmu. the other something they wrote theirself to setup MS SQL Servers at customer sites fully automatic.
With the regular customers no false Positive seen with the AMSI.
Read my links about AMSI and Powershell which are alwayws mentioned at Blackhat.
http://www.butsch.ch/post/Mcafee-Endpoint-Security-ENS-106-Release-news.aspx
I have a quick quesion on this topic - is there a way to test AMSI? I just setup some alerts in ePO for AMSI detections, but just wondered if there's an EICAR-esque test file that can be used to make sure the alerts are setup correctly?
I have Googled this but can't find a solution.
Thanks for any help you can give me.
Thanks for your response, I will take a look at my ENS IPS rules.
Do you know if there is a test script that can be used to trigger an AMSI detection?
Thanks again,
Adam
Thanks Cara, you solved my issue!
If anyone else is wondering, yes, McAfee can provide you with files that can be used to test that your AMSI is properly configured and that any alerts you have setup via automated responses are also triggered properly.
Thanks,
Adam
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA