Hello, We are getting a lot of Alerts on our Palo Alto Firewall that is saying TCP-Over-DNS Traffic Evasion Application Detection.
The reason I'm asking this here is the firewall is saying the traffic is coming from Sophos-live-protection.
I was hoping someone would know if the Sophos Central Endpoints send TCP Packets over DNS? If it does, then we can ignore these alerts.
Thanks for your help
This thread was automatically locked due to age.