cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2979
Views
25
Helpful
4
Replies

Anyone else seeing this FP?

Getting a stack of DFC Threat Detected for an ip...

205[.]185[.]216[.]42

Its a CDN in Texas... 

Talos says it's bad... but its resolving to things like dl.delivery.mp.microsoft.com, etc.

1 Accepted Solution

Accepted Solutions

Looks like a false positive, and should be fixed now.

View solution in original post

4 Replies 4

Troja007
Cisco Employee
Cisco Employee

Hello @Ken Stieers,
talos is already investigating the issue. Should be fixed soon.
Greetings,
Thorsten

It's been 2 hours now since our system picked it up from AMP and Firepower.   Is this false positive or for real?   

Looks like a false positive, and should be fixed now.

soup_dragon
Level 1
Level 1

Thanks for posting, starting to consider isolating so pleased you posted this as when looking into the detail didn’t stack up.