<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IDM alert monitoring in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/idm-alert-monitoring/m-p/1076661#M79267</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had the exact same issue going on at my location, and there were two causes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One was that we had a bluecoat proxy, which uses multiple ports to refresh its website cache, and for new requests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other cause was a machine that was infested with spyware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is a users machine, I would suggest downloading the Sysinternals Suite from Microsoft, and doing a PSLOGGEDON \\&lt;IP&gt; to see who is using that machine.&lt;/IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 06 Aug 2008 16:25:30 GMT</pubDate>
    <dc:creator>jason.hurst</dc:creator>
    <dc:date>2008-08-06T16:25:30Z</dc:date>
    <item>
      <title>IDM alert monitoring</title>
      <link>https://community.cisco.com/t5/network-security/idm-alert-monitoring/m-p/1076659#M79265</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Monitoring the IDM alerts show that one of the internal clients attacking outside IP addresses. Couls someone shed light on the above dynamics.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Said&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;evIdsAlert: eventId=1216735955474843112  vendor=Cisco  severity=informational  &lt;/P&gt;&lt;P&gt;  originator:   &lt;/P&gt;&lt;P&gt;    hostId: ips  &lt;/P&gt;&lt;P&gt;    appName: sensorApp  &lt;/P&gt;&lt;P&gt;    appInstanceId: 406  &lt;/P&gt;&lt;P&gt;  time: Jul 29, 2008 12:50:48 UTC  offset=0  timeZone=UTC  &lt;/P&gt;&lt;P&gt;  signature:   description=TCP SYN Host Sweep  id=3030  version=S2  &lt;/P&gt;&lt;P&gt;    subsigId: 0  &lt;/P&gt;&lt;P&gt;    marsCategory: Probe/SpecificPorts  &lt;/P&gt;&lt;P&gt;  interfaceGroup: vs0  &lt;/P&gt;&lt;P&gt;  vlan: 0  &lt;/P&gt;&lt;P&gt;  participants:   &lt;/P&gt;&lt;P&gt;    attacker:   &lt;/P&gt;&lt;P&gt;      addr: 192.168.1.207  locality=OUT  &lt;/P&gt;&lt;P&gt;      port: 4580  &lt;/P&gt;&lt;P&gt;    target:   &lt;/P&gt;&lt;P&gt;      addr: 66.150.11.50  locality=OUT  &lt;/P&gt;&lt;P&gt;      os:   idSource=unknown  type=unknown  relevance=relevant  &lt;/P&gt;&lt;P&gt;    target:   &lt;/P&gt;&lt;P&gt;      addr: 68.180.219.138  locality=OUT  &lt;/P&gt;&lt;P&gt;      os:   idSource=learned  type=bsd  relevance=relevant  &lt;/P&gt;&lt;P&gt;    target:   &lt;/P&gt;&lt;P&gt;      addr: 74.201.95.4  locality=OUT  &lt;/P&gt;&lt;P&gt;      os:   idSource=unknown  type=unknown  relevance=relevant  &lt;/P&gt;&lt;P&gt;    target:   &lt;/P&gt;&lt;P&gt;      addr: 72.247.169.161  locality=OUT  &lt;/P&gt;&lt;P&gt;      os:   idSource=unknown  type=unknown  relevance=relevant  &lt;/P&gt;&lt;P&gt;    target:   &lt;/P&gt;&lt;P&gt;      addr: 207.230.151.254  locality=OUT  &lt;/P&gt;&lt;P&gt;      os:   idSource=unknown  type=unknown  relevance=relevant  &lt;/P&gt;&lt;P&gt;    target:   &lt;/P&gt;&lt;P&gt;      addr: 216.252.124.207  locality=OUT  &lt;/P&gt;&lt;P&gt;      os:   idSource=learned  type=bsd  relevance=relevant  &lt;/P&gt;&lt;P&gt;    target:   &lt;/P&gt;&lt;P&gt;      addr: 67.228.69.100  locality=OUT  &lt;/P&gt;&lt;P&gt;      os:   idSource=unknown  type=unknown  relevance=relevant  &lt;/P&gt;&lt;P&gt;    target:   &lt;/P&gt;&lt;P&gt;      addr: 208.43.2.146  locality=OUT  &lt;/P&gt;&lt;P&gt;      os:   idSource=unknown  type=unknown  relevance=relevant  &lt;/P&gt;&lt;P&gt;    target:   &lt;/P&gt;&lt;P&gt;      addr: 66.196.126.101  locality=OUT  &lt;/P&gt;&lt;P&gt;      os:   idSource=unknown  type=unknown  relevance=relevant  &lt;/P&gt;&lt;P&gt;    target:   &lt;/P&gt;&lt;P&gt;      addr: 69.22.167.239  locality=OUT  &lt;/P&gt;&lt;P&gt;      os:   idSource=unknown  type=unknown  relevance=relevant  &lt;/P&gt;&lt;P&gt;    target:   &lt;/P&gt;&lt;P&gt;      addr: 216.73.87.152  locality=OUT  &lt;/P&gt;&lt;P&gt;      os:   idSource=unknown  type=unknown  relevance=relevant  &lt;/P&gt;&lt;P&gt;    target:   &lt;/P&gt;&lt;P&gt;      addr: 12.130.60.4  locality=OUT  &lt;/P&gt;&lt;P&gt;      os:   idSource=unknown  type=unknown  relevance=relevant  &lt;/P&gt;&lt;P&gt;    target:   &lt;/P&gt;&lt;P&gt;      addr: 66.94.234.72  locality=OUT  &lt;/P&gt;&lt;P&gt;      os:   idSource=unknown  type=unknown  relevance=relevant  &lt;/P&gt;&lt;P&gt;    target:   &lt;/P&gt;&lt;P&gt;      addr: 216.145.50.247  locality=OUT  &lt;/P&gt;&lt;P&gt;      os:   idSource=unknown  type=unknown  relevance=relevant  &lt;/P&gt;&lt;P&gt;    target:   &lt;/P&gt;&lt;P&gt;      addr: 216.252.125.76  locality=OUT  &lt;/P&gt;&lt;P&gt;      os:   idSource=learned  type=bsd  relevance=relevant  &lt;/P&gt;&lt;P&gt;    target:   &lt;/P&gt;&lt;P&gt;      addr: 209.131.37.77  locality=OUT  &lt;/P&gt;&lt;P&gt;      os:   idSource=learned  type=bsd  relevance=relevant  &lt;/P&gt;&lt;P&gt;  alertDetails: InterfaceAttributes:  context="Unknown" physical="Unknown" backplane="GigabitEthernet0/1" ;  &lt;/P&gt;&lt;P&gt;  riskRatingValue: 31  targetValueRating=medium  attackRelevanceRating=relevant  &lt;/P&gt;&lt;P&gt;  threatRatingValue: 31  &lt;/P&gt;&lt;P&gt;  interface: GigabitEthernet0/1  context=Unknown  physical=Unknown  backplane=GigabitEthernet0/1  &lt;/P&gt;&lt;P&gt;  protocol: tcp &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 11:13:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idm-alert-monitoring/m-p/1076659#M79265</guid>
      <dc:creator>saidfrh</dc:creator>
      <dc:date>2019-03-10T11:13:32Z</dc:date>
    </item>
    <item>
      <title>Re: IDM alert monitoring</title>
      <link>https://community.cisco.com/t5/network-security/idm-alert-monitoring/m-p/1076660#M79266</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A host sweep does not equal an attack.  We don't have the destination port here so this could simply be outbound web traffic from a proxy server or outbound mail traffic from your mail server.  Perform a packet display on the sensor to see what connections the above IP is making (look at the destination port) and also look for other events with this same source.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jul 2008 16:03:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idm-alert-monitoring/m-p/1076660#M79266</guid>
      <dc:creator>attmidsteam</dc:creator>
      <dc:date>2008-07-30T16:03:54Z</dc:date>
    </item>
    <item>
      <title>Re: IDM alert monitoring</title>
      <link>https://community.cisco.com/t5/network-security/idm-alert-monitoring/m-p/1076661#M79267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had the exact same issue going on at my location, and there were two causes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One was that we had a bluecoat proxy, which uses multiple ports to refresh its website cache, and for new requests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The other cause was a machine that was infested with spyware.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is a users machine, I would suggest downloading the Sysinternals Suite from Microsoft, and doing a PSLOGGEDON \\&lt;IP&gt; to see who is using that machine.&lt;/IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jason&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 16:25:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idm-alert-monitoring/m-p/1076661#M79267</guid>
      <dc:creator>jason.hurst</dc:creator>
      <dc:date>2008-08-06T16:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: IDM alert monitoring</title>
      <link>https://community.cisco.com/t5/network-security/idm-alert-monitoring/m-p/1076662#M79268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason,&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Said&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 17:05:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idm-alert-monitoring/m-p/1076662#M79268</guid>
      <dc:creator>saidfrh</dc:creator>
      <dc:date>2008-08-06T17:05:16Z</dc:date>
    </item>
    <item>
      <title>Re: IDM alert monitoring</title>
      <link>https://community.cisco.com/t5/network-security/idm-alert-monitoring/m-p/1076663#M79269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jason,&lt;/P&gt;&lt;P&gt;I downloaded and unzipped Sysinternals Suite. Wwhere do I type in PSLOGGEDON \\&lt;IP&gt; ?&lt;/IP&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 17:29:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idm-alert-monitoring/m-p/1076663#M79269</guid>
      <dc:creator>saidfrh</dc:creator>
      <dc:date>2008-08-06T17:29:09Z</dc:date>
    </item>
    <item>
      <title>Re: IDM alert monitoring</title>
      <link>https://community.cisco.com/t5/network-security/idm-alert-monitoring/m-p/1076664#M79270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I ran a spyware program on machines that "attcked" outside IPs  There were mo spyware found.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Aug 2008 19:38:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idm-alert-monitoring/m-p/1076664#M79270</guid>
      <dc:creator>saidfrh</dc:creator>
      <dc:date>2008-08-06T19:38:49Z</dc:date>
    </item>
  </channel>
</rss>

