- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
AMP : disposition "malicious" allowed
Hello community,
My Meraki Security Dashboard inform me that a malware was downloaded on my network.
I can't find any informations about this file. Can you please tell me more ? And why a malicious file was allowed by my MX device ?
Thank you for your help and best regards,
David
Solved! Go to solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please follow this topic : Advanced Malware Protection (AMP) retrospect alert - The Meraki Community
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Interesting. Under your IDS settings, are you set for Prevention or just Detection?
I have the same alerts, but mine are showing as Blocked.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
After performing several tests, this problem occurs when updating MS Office.
Apparently Meraki's AMP service identifies files as malicious (false positive) :
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Meraki is aware of the issue and are investigating.
It's believed to be a false positive caused by an O365 update.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Please follow this topic : Advanced Malware Protection (AMP) retrospect alert - The Meraki Community
