<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FirePower Security Intelligence Question in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-security-intelligence-question/m-p/3958175#M17956</link>
    <description>Thanks Sheraz,&lt;BR /&gt;I don't necessarily think the URL is malicious, but Talos thinks it is which causes a lot of IOC's every day for hosts on our network. I just blacklisted the URL(s) and the IOC's went away. Nobody has complained yet. That's probably going to be how I resolve this in the future. Blacklist and be done with it.&lt;BR /&gt;Thanks!</description>
    <pubDate>Wed, 13 Nov 2019 18:51:31 GMT</pubDate>
    <dc:creator>-Sparrow-</dc:creator>
    <dc:date>2019-11-13T18:51:31Z</dc:date>
    <item>
      <title>FirePower Security Intelligence Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-security-intelligence-question/m-p/3955105#M17924</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've noticed an increase in IOC's being triggered due to hosts attempting to access&amp;nbsp;&lt;A href="https://gogo.thepowerrangers.com" target="_blank" rel="noopener"&gt;hxxps://gogo.thepowerrangers.com&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;End users are obviously not trying to get to a power rangers site.&amp;nbsp; It seems to be a URL redirect.&amp;nbsp; Has anyone else found their FirePower SI blocking this site? It's happening multiple times a day and I'm unsure what's triggering this. Google is not my friend here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had the same issue a few weeks ago with&amp;nbsp;&lt;A href="https://mv-s2s-dev.ngrok.io.&amp;nbsp;" target="_blank" rel="noopener"&gt;hxxps://mv-s2s-dev.ngrok.io.&amp;nbsp;&lt;/A&gt; That URL has subsided for the time being.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 07 Nov 2019 20:42:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-security-intelligence-question/m-p/3955105#M17924</guid>
      <dc:creator>-Sparrow-</dc:creator>
      <dc:date>2019-11-07T20:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower Security Intelligence Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-security-intelligence-question/m-p/3956193#M17947</link>
      <description>&lt;P&gt;To check the URL health go to &lt;A href="https://www.brightcloud.com/tools/url-ip-lookup.php" target="_blank"&gt;https://www.brightcloud.com/tools/url-ip-lookup.php&lt;/A&gt; check firepower url engine use the statistics from this engine.&lt;/P&gt;&lt;P&gt;now coming back to your point. if you think this url is malicious and you need to block the rule &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/60/configuration/guide/fpmc-config-guide-v60/Access_Control_Rules__URL_Filtering.html" target="_self"&gt;here&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 09 Nov 2019 21:44:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-security-intelligence-question/m-p/3956193#M17947</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-11-09T21:44:09Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower Security Intelligence Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-security-intelligence-question/m-p/3958175#M17956</link>
      <description>Thanks Sheraz,&lt;BR /&gt;I don't necessarily think the URL is malicious, but Talos thinks it is which causes a lot of IOC's every day for hosts on our network. I just blacklisted the URL(s) and the IOC's went away. Nobody has complained yet. That's probably going to be how I resolve this in the future. Blacklist and be done with it.&lt;BR /&gt;Thanks!</description>
      <pubDate>Wed, 13 Nov 2019 18:51:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-security-intelligence-question/m-p/3958175#M17956</guid>
      <dc:creator>-Sparrow-</dc:creator>
      <dc:date>2019-11-13T18:51:31Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower Security Intelligence Question</title>
      <link>https://community.cisco.com/t5/network-security/firepower-security-intelligence-question/m-p/3958193#M17968</link>
      <description>&lt;P&gt;Yes, you can always utilize the white/blacklist in such situations. Also, just to mention, you can always submit a dispute directly to TALOS through the following link:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://talosintelligence.com/reputation_center/support" target="_blank"&gt;https://talosintelligence.com/reputation_center/support&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Thank you for rating helpful posts!&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2019 19:14:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-security-intelligence-question/m-p/3958193#M17968</guid>
      <dc:creator>nspasov</dc:creator>
      <dc:date>2019-11-13T19:14:06Z</dc:date>
    </item>
  </channel>
</rss>

