04-30-2020 06:39 AM
What is the source that Cisco is referring to block the IP address under "Network" tab, Where can we find the source for this so that we can customize if required.
04-30-2020 07:21 AM
AMP uses a subset of the TALOS Intelligence IP Blacklist. To create your own list, you can go to Outbreak Control > IP Block & Allow Lists. Once your list is created, go to edit your policy and add it in the Outbreak Control section.
Under Advanced Settings > Network, you can choose to use Cisco's list, Cisco and Custom, or just your Custom lists.
Thanks,
Matt
04-30-2020 07:28 AM
Thanks Matthew, So is this list dynamically updated by Cisco based on new threats. Is my understanding right?
04-30-2020 08:04 AM
That is correct. The list is regularly updated by TALOS.
Thanks,
Matt
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide