06-20-2012 01:03 PM - edited 03-10-2019 05:42 AM
How can i detect low and slow data exfiltration with the Cisco IPS?
06-26-2012 11:12 AM
This is a valid question. Let's get some discussion going here.
Bob, you wouldn't happen to be talking about 3.H.1. would you?
06-26-2012 11:36 AM
Yes I am talking about 3.H.1 also looking at 3.H.1.B I was going to create a custom Signatures that looks for ZIP and RAR files for the compressed files.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide