Cisco Secure Endpoint high number of malicious files from single host

This rule is part of a beta feature. To learn more, contact Support.

Goal

Detect an unusually high number of unique malicious files from a single host.

Strategy

This rule monitors events to detect a spike in the number of malicious files from single host.

Triage and response

  1. Investigate the Host, {{@event.computer.hostname}}, in which the malicious files have been detected.
  2. Analyze the endpoint for other potentially malicious activity.
  3. Implement immediate measures to block or limit the impact of the suspicious activity if confirmed as a threat.
  4. Follow company procedures for handling malicious files, including isolating the endpoint, running antivirus/antimalware scans, analyzing logs, and updating security policies.