University of Wisconsin–Madison

Join us for a lunch and learn training session for Cisco AMP on Oct 31

(Email message)

IT Colleagues: 

The Office of Cybersecurity will be hosting a lunch and learn training session for Cisco AMP on October 31st. The purpose of the session is to familiarize and train IT admins across campus with the AMP endpoint connector and the AMP administrative console. While we encourage in-person attendance, you will have the option to attend remotely via Webex (details below). In addition to the structured agenda outlined below, there is a significant portion of time set aside for questions – so come prepared to participate!

Cicso AMP Brownbag

11:30am-1:00pm
October 31st
Computer Science Building, Room 3139BC 

Webex Meeting URL: https://uwmadison.webex.com/uwmadison/j.php?MTID=ma4fe7a0a9eb843a904a18f146559bc77
Meeting Code: 921 803 997
Password: Wp7bf2Xm

 Agenda:

  1. Brief introduction to AMP connector and how it functions (10 minutes)
  2. Getting started (5 minutes):
  3. Requesting AMP console account & endpoint connectors
  4. Downloading the AMP connector
  5. Deployment options available through BigFix, SCCM, JAMF, Airwatch, etc.    
  6. Detailed Threat Analysis in the AMP Console (10-15 minutes)
    1. Viewing and reviewing events
    2. Drilling down into the details
  1. Tuning for performance (10-15 minutes)
    1. Whitelisting files
    2. Setting up exclusions
  1. Configuring policy settings and detection engines (15 minutes)
    1. Tetra/Clam AV traditional AV scanning (and scheduling scans)
    2. File, Network, Malicious Activity Protection, System Process Protection detection engines
    3. Enabling/disabling the local GUI
  1. Maintenance (5-10 minutes) 
  2. Updating AMP via the console
  3. What happens with imaging/duplicate endpoints?
  4. Checking endpoint health & known issues
  5. Answer audience questions regarding AMP (remaining time)

Contact Information:

If you have questions that you would like added to the agenda, or questions in general, email oakes.dobson@wisc.edu

 

-The Office of Cybersecurity