Active Threat Response

Hello,

Yesterday, I got the ATR dropping a request made to a potential threat. The thing is, that the source threat was our DNS/DHCP server, and the threat destination is "stylesheet.webstaticcdn.com" with no ip or trace.

I've starte a full scan, everything seems fine.

Is there any thing could I do to know what exactly happened?

this issue occured 9 times in the same day.

Regards,

Thank you.

Parents
  • Thank you for reaching out to the community forum.

    Regarding your concern, what Product subscription are you currently using? Are you using IX advanced with XDR? If so? have you checked your threat analysts Center? You may be able to find more information about the said detection when you go to that feature. 

    Glenn ArchieSeñas (GlennSen)
    Global Community Support Engineer

    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Reply
  • Thank you for reaching out to the community forum.

    Regarding your concern, what Product subscription are you currently using? Are you using IX advanced with XDR? If so? have you checked your threat analysts Center? You may be able to find more information about the said detection when you go to that feature. 

    Glenn ArchieSeñas (GlennSen)
    Global Community Support Engineer

    The New Home of Sophos Support Videos!  Visit Sophos Techvids
Children
No Data