03-20-2024 08:36 AM
Hi,
Our antivirus software keeps detecting and blocking "OS detection" intrusions originating from one of our cisco switches.
Does anyone have an idea what could be triggering the intrusion detection? My first thought was that maybe CDP wasn't playing nice with the software but even after disabling it we get the same intrusion detections.
03-20-2024 09:03 AM
Would you mind sharing the intrusion event for review?
03-20-2024 09:10 AM
This is what we see in our AV dashboard.
We could of course simply enable an exception for the switch IP but since we're not yet sure whether it's a false positive or an actual intrusion attempt we'd rather not at this time.
03-20-2024 09:35 AM
Mmm, it does not say much. I would try to look at the documentation to trying to see what values would trigger the OS Detection event and take it from there.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide