Hi,
is there any mcafee list for covered signature amcore content/dat ? i want to match which malware or ransomware that have been and not yet covered by mcafee,]
because we use mcafee enstp and planning to add atp but our customer want the list first,
regards,
Dwi
Hello @Dwee,
Unfortunately, there is no list of malware,virus,pup that can be detected by amcore.
Thanks,
ENS ATP is much more than the extra detections.
And ENS 10.7 includes Adaptive Threat Protection by default
https://kc.mcafee.com/corporate/index?page=content&id=KB92270&locale=en_US
The Enhanced remediation:
Story graph with increased context for ATP detections:
ENS 10.7 release notes:
Hi Nielsb,
thanks for your reply, we know that atp not depends on signature like TP, but our customer wants some prove with seeing believing in this case, signatures already add in dat/amcore content, so i'm a bit confuse how to give prove for that, because their db sql server have been attack with lemon duck and others malware using "eternal blue" and brute force tricks and myself already suggest to reset the ad password beside adding extra dats and tweak the policies, sadly our customer want's mcafee enstp to be powerfull tools (example, using stinger clicked in the infected machine than run and clean/delete) not just blocked using "AMSI" scanner metode, so he wants some prove "is extra dats and mcafee enstp product" really do the job done" ,
You can show your customer the datasheet below
https://www.mcafee.com/enterprise/en-us/assets/data-sheets/ds-endpoint-security.pdf
page 6 the features and why you need a feature/module and the layered approach, the different layers of ENS + ATP
1. whitelisting (hash+cert)
(access protection policy)
2. Content files (AMcore/exploit prevention
3. GTI
4. TIE (hash + cert)
5. Real protect - static code
6. Dynamic APP containment
7. Real protect ( behavioral)
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA