<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Security information on IP address or URL in Sourcefire in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/security-information-on-ip-address-or-url-in-sourcefire/m-p/2736967#M18464</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I recently deployed SFR module on ASA 5512-X and I am facing the following issue : One website that is used on a daily basis is blocked since we deployed FirePower services. Actually, it's been categorized as "Malware Site" with a bad reputation "High Risk".&lt;/P&gt;&lt;P&gt;I added this URL to a white list so it can be reached but the customer asks to gather some information on why it's been categorized like this. My question is : is there a Sourcefire or Cisco tool where we can see the history of a particular domain or IP address ?&lt;/P&gt;&lt;P&gt;I checked on senderbase.org but there is no information like this and I know Sourcefire doesn't use SenderBase anyway.&lt;/P&gt;&lt;P&gt;My guess is maybe this website has been hacked in the past and is delivering malware since.&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Vincent&lt;/P&gt;</description>
    <pubDate>Thu, 08 Oct 2015 11:01:29 GMT</pubDate>
    <dc:creator>Vincent Fortrat</dc:creator>
    <dc:date>2015-10-08T11:01:29Z</dc:date>
    <item>
      <title>Security information on IP address or URL in Sourcefire</title>
      <link>https://community.cisco.com/t5/network-security/security-information-on-ip-address-or-url-in-sourcefire/m-p/2736967#M18464</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I recently deployed SFR module on ASA 5512-X and I am facing the following issue : One website that is used on a daily basis is blocked since we deployed FirePower services. Actually, it's been categorized as "Malware Site" with a bad reputation "High Risk".&lt;/P&gt;&lt;P&gt;I added this URL to a white list so it can be reached but the customer asks to gather some information on why it's been categorized like this. My question is : is there a Sourcefire or Cisco tool where we can see the history of a particular domain or IP address ?&lt;/P&gt;&lt;P&gt;I checked on senderbase.org but there is no information like this and I know Sourcefire doesn't use SenderBase anyway.&lt;/P&gt;&lt;P&gt;My guess is maybe this website has been hacked in the past and is delivering malware since.&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;Vincent&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 11:01:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-information-on-ip-address-or-url-in-sourcefire/m-p/2736967#M18464</guid>
      <dc:creator>Vincent Fortrat</dc:creator>
      <dc:date>2015-10-08T11:01:29Z</dc:date>
    </item>
    <item>
      <title>I think Sourcefire uses</title>
      <link>https://community.cisco.com/t5/network-security/security-information-on-ip-address-or-url-in-sourcefire/m-p/2736968#M18488</link>
      <description>&lt;P&gt;I think Sourcefire uses brightcloud as a web reputation. Check how categorized is website you are accessing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.brightcloud.com/tools/change-request-url-ip.php&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 13:49:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-information-on-ip-address-or-url-in-sourcefire/m-p/2736968#M18488</guid>
      <dc:creator>alberx</dc:creator>
      <dc:date>2015-10-08T13:49:05Z</dc:date>
    </item>
    <item>
      <title>Exactly what I was looking</title>
      <link>https://community.cisco.com/t5/network-security/security-information-on-ip-address-or-url-in-sourcefire/m-p/2736969#M18508</link>
      <description>&lt;P&gt;Exactly what I was looking for ! Thanks !&lt;/P&gt;&lt;P&gt;Do you know if FirePower will use Cisco Security Intelligence in the future instead of Brightcloud ?&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 13:54:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-information-on-ip-address-or-url-in-sourcefire/m-p/2736969#M18508</guid>
      <dc:creator>Vincent Fortrat</dc:creator>
      <dc:date>2015-10-08T13:54:58Z</dc:date>
    </item>
    <item>
      <title>I don´t know any about</title>
      <link>https://community.cisco.com/t5/network-security/security-information-on-ip-address-or-url-in-sourcefire/m-p/2736970#M18524</link>
      <description>&lt;P&gt;I don´t know any about SourceFire roadmaps. Sorry.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Oct 2015 14:17:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/security-information-on-ip-address-or-url-in-sourcefire/m-p/2736970#M18524</guid>
      <dc:creator>alberx</dc:creator>
      <dc:date>2015-10-08T14:17:14Z</dc:date>
    </item>
  </channel>
</rss>

