<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Yes - you use Correlation in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-firesight-blacklist-an-ip-after-it-identifies-malware-from/m-p/3034856#M988946</link>
    <description>&lt;P&gt;Yes - you use Correlation Policy with rules and remediations for this.&lt;/P&gt;
&lt;P&gt;The logic of doing it is a bit complex (in my opinion) but you can watch the excellent labminutes video on this topic to learn how.&lt;/P&gt;
&lt;P&gt;http://www.labminutes.com/sec0177_asa_firepower_event_correlation_remediation_1&lt;/P&gt;</description>
    <pubDate>Fri, 09 Jun 2017 03:25:38 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2017-06-09T03:25:38Z</dc:date>
    <item>
      <title>Can FireSight blacklist an IP after it identifies malware from them</title>
      <link>https://community.cisco.com/t5/network-security/can-firesight-blacklist-an-ip-after-it-identifies-malware-from/m-p/3034855#M988930</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;We have FirePower managed by FireSight, and i was wondering, can you get FireSight to blacklist an IP when it say identifies the sender as emailing malware?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Or set an IPS policy to blacklist the source IP address when a malware event is triggered, &amp;nbsp;for a period of say 24 hours?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank You&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Chris&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:25:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-firesight-blacklist-an-ip-after-it-identifies-malware-from/m-p/3034855#M988930</guid>
      <dc:creator>paul-d</dc:creator>
      <dc:date>2019-03-12T13:25:06Z</dc:date>
    </item>
    <item>
      <title>Yes - you use Correlation</title>
      <link>https://community.cisco.com/t5/network-security/can-firesight-blacklist-an-ip-after-it-identifies-malware-from/m-p/3034856#M988946</link>
      <description>&lt;P&gt;Yes - you use Correlation Policy with rules and remediations for this.&lt;/P&gt;
&lt;P&gt;The logic of doing it is a bit complex (in my opinion) but you can watch the excellent labminutes video on this topic to learn how.&lt;/P&gt;
&lt;P&gt;http://www.labminutes.com/sec0177_asa_firepower_event_correlation_remediation_1&lt;/P&gt;</description>
      <pubDate>Fri, 09 Jun 2017 03:25:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-firesight-blacklist-an-ip-after-it-identifies-malware-from/m-p/3034856#M988946</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-06-09T03:25:38Z</dc:date>
    </item>
  </channel>
</rss>

