Cisco Secure Endpoint high number of malicious files from single host

This rule is part of a beta feature. To learn more, contact Support.
이 페이지는 아직 한국어로 제공되지 않으며 번역 작업 중입니다. 번역에 관한 질문이나 의견이 있으시면 언제든지 저희에게 연락해 주십시오.

Goal

Detect an unusually high number of unique malicious files from a single host.

Strategy

This rule monitors events to detect a spike in the number of malicious files from single host.

Triage and response

  1. Investigate the Host, {{@event.computer.hostname}}, in which the malicious files have been detected.
  2. Analyze the endpoint for other potentially malicious activity.
  3. Implement immediate measures to block or limit the impact of the suspicious activity if confirmed as a threat.
  4. Follow company procedures for handling malicious files, including isolating the endpoint, running antivirus/antimalware scans, analyzing logs, and updating security policies.