Cisco Secure Endpoint high number of malicious files from single host

This rule is part of a beta feature. To learn more, contact Support.
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください

Goal

Detect an unusually high number of unique malicious files from a single host.

Strategy

This rule monitors events to detect a spike in the number of malicious files from single host.

Triage and response

  1. Investigate the Host, {{@event.computer.hostname}}, in which the malicious files have been detected.
  2. Analyze the endpoint for other potentially malicious activity.
  3. Implement immediate measures to block or limit the impact of the suspicious activity if confirmed as a threat.
  4. Follow company procedures for handling malicious files, including isolating the endpoint, running antivirus/antimalware scans, analyzing logs, and updating security policies.