• Advanced Threat Protection research

    William Capeless
    William Capeless
    I am having trouble determining what is happening here. I see the source is google dns, the destination is my internal dns server. the threat is clickmatters.biz. How do I track this down to find out what is going on. I checked web logs to see if anyone…
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • ATP false positive?

    Ben@Network
    Ben@Network
    Hello Communitiy, from time to time we have some false positives on APT. If I check the URL with VirusTotal often Sophos is the only vendor where the URL marked as "Malicious". An example is this URL: https://coronalevel.com/Germany If I check the…
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • ATP block all *.idv.tw FQDN query!?

    Shunze Lee
    Shunze Lee
    We found all the *. idv.tw domains were blocked by ATP with XG. I have opened a case (ID: 04765685) to Sophos, but Sophos seems doesn't know the issue? Shunze
    • Answered
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • ATP reporting external IP as source

    HPC Kronos
    HPC Kronos
    Hello, I found this old thread but didn't find it helpful. https://community.sophos.com/sophos-xg-firewall/f/discussions/124646/atp-reporting-external-ip-as-source From the ATP reports I am seeing Google and Cloudflare DNSs being reported. …
    • over 2 years ago
    • Sophos Firewall
    • Discussions
  • alerts keep scaling

    Taoufik MOURTADI
    Taoufik MOURTADI
    does anybody know what the cause of this alert ? also i want to stop it from it source ?
    • over 3 years ago
    • Sophos Firewall
    • Discussions
  • ATP reports "C2/Generic-A" :

    NM_1987
    NM_1987
    Hello some of our customers asked me about this so I think this will help others, too. 2021-10-18 10:24:07 192.168.36.181 enabaonag_laptop 192.168.36.1 C2/Generic-A www.google.com.512542883555094…
    • Answered
    • over 3 years ago
    • Sophos Firewall
    • Discussions
  • View related content throughout Sophos Firewall
  • More
  • Cancel
<