cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1338
Views
0
Helpful
1
Replies

Security Intelligence Events

slymer1965
Level 1
Level 1

Is there any way to drill into a Security Intelligence Event in Sourcefire? I am seeing numerous outbound CnC events coming from a host but cannot see what application, service, etc. is causing the triggered event.

Thanks!!

Scot Lymer

1 Reply 1

Dennis Perto
Level 5
Level 5

Hi

Unfortunately there is no way of doing that.

Security Intelligence is the same as Blacklists. It stops the traffic before it knows what Application/Protocol that is used.

Review Cisco Networking for a $25 gift card