
It shows the point in time when a virus is downloaded, so you can see if the user was surfing the internet or had a program open.

Once a threat was detected, being able to do the threat lookups and the live tracking was really useful." "Another of my favorite features is called the Device Trajectory, where it shows everything that's going on, on a computer. We had Umbrella in place and we were using An圜onnect as well as Firepower. It should protect all kinds of things that might happen on the servers, things that I cannot see." "The threat Grid with the ability to observe the sandboxing, analyze, and perform investigations of different malicious files has been great." "The most valuable feature is signature-based malware detection." "The integration with other Cisco products seemed to be really effective. It allows for research into a threat, and you can chart your progress on how you're resolving it." "I'm only using the AMP (advanced malware protection) which is protecting my file system from all the malicious things that might happen. And on the scalability side, we can integrate well with the SIEM orchestration engine and a number of applications that are proprietary or open source." "It is extensive in terms of providing visibility and insights into threats. We're able to dig in and really understand how things came to be and where to focus our efforts." "Among the most valuable features are the exclusions. "Device Trajectory is one of the most valuable features.
