Hello,
I have detected a file that was flagged by our Cisco Endpoint protection.
File Name: Get-NewLocalAdmin.ps1
Detection: W32.CFAB3E3BCA-95.SBX.TG
SHA 256: cfab3e3bca1517a535358cef7b206c65abb02470495ac929ca7b3ee0cfe3fab8
It looks like it spread across a lot of our computers and servers but it was denied. I have put it under the blocked application list.
I also found another file called "Set-LocalAdmin.ps1"
They were created in the ProgramData folder and the folder was called _Automation
I would like any advice if possible!
![File Detected.png File Detected.png](https://community.meraki.com/t5/image/serverpage/image-id/35394iB46F653C03A71FE7/image-size/medium?v=v2&px=400)
![Location of File on End User.png Location of File on End User.png](https://community.meraki.com/t5/image/serverpage/image-id/35393iA2D3CD716DC0A53F/image-size/medium?v=v2&px=400)