bo3500001
Level 1
Level 1
Member since ‎12-20-2015
‎12-26-2019

User Statistics

  • 13 Posts
  • 0 Solutions
  • 2 Helpful votes Given
  • 0 Helpful votes Received
Recent Badges
First Discussion
5 Discussion Posts
10 Discussion Posts
1 Reply
CCP Member
5 Replies

User Activity

Is there a way to create a device profiling condition/policy based on data arriving from PassiveID?  For example, Passive Authentication record arrives over WMI, if end point in subnet range, activate NMAP os scan?  Thanks!
Recently updated FMC to 6.2.0.1.  Estreamer client now only sends 5 or so events and then the estreamer client fails, both on Splunk and host-based client testing.   Also, the server does not seem to respond to changes in the event type delivery opti...
I am trying to find a way to integrate Splunk and the FireSight Database using the Database access API.  Currently, we are using eStreamer for low volume events and syslog alerting for high volume events, such as connection events (as eStreamer choke...
Is there a way with either a Simple or Advanced Custom detection to stop a browser extension install or to remove/detect an existing one?  Can you configure an IOC scan to Quarantine a file?
We are having an issue with IP Black/White list.  We've developed a containment policy which whitelists several necessary addresses (e.g. AMP addresses and DNS services), and configured the blacklist to the rest of the network's private IP address sp...
Community Statistics
Member Since ‎12-20-2015 12:15 PM
Date Last Visited ‎12-26-2019 02:53 PM
Posts 13
Helpful Votes Given To