Cisco Cisco Firepower Management Center 4000

Page of 1844
 
5-35
FireSIGHT System User Guide
 
Chapter 5      Managing Reusable Objects
  Working with File Lists
Adding a SHA-256 Value to the File List
License: 
Malware
Supported Devices: 
Series 3, Virtual, X-Series, ASA FirePOWER
Supported Defense Centers: 
Any except DC500
You can submit a file’s SHA-256 value to add it to a file list. You cannot add duplicate SHA-256 values.
Tip
Right-click a file or malware event from the event view and select 
Show Full Text
 in the context menu to 
view and copy the full SHA-256 value for the file.
To add a file by manually entering the file’s SHA-256 value:
Access: 
Admin/Network Admin
Step 1
On the object manager’s File List page, click the edit icon (
) next to the clean list or custom detection 
list where you want to add a file.
The File List pop-up window appears.
Step 2
Select 
Enter SHA Value 
from the 
Add by
 field.
The pop-up window updates to include new fields.
Step 3
Enter a description of the source file in the 
Description
 field. 
Step 4
Type or paste the file’s entire 
SHA-256
 value. The system does not support matching partial values.
Step 5
Click 
Add
 to add the file.
The file is added to the file list. 
Step 6
Click 
Save
Step 7
Reapply all access control policies with file policies that use the file list.
After the policies apply, the system no longer performs malware cloud lookups on files in the file list.
Modifying Files on a File List
License: 
Malware
Supported Devices: 
Series 3, Virtual, X-Series, ASA FirePOWER
Supported Defense Centers: 
Any except DC500
You can edit or delete individual SHA-256 values on a file list. Note that you cannot directly edit a source 
file within the object manager. To make changes, you must first modify your source file directly, delete 
the copy on the system, then upload the modified source file. See 
 for more information. To edit a file on a file list:
Access: 
Admin/Network Admin
Step 1
On the object manager’s File List page, click the edit icon (
) next to the clean list or custom detection 
list where you want to modify a file.