Endpoint Protection

 View Only
  • 1.  best practise applying on srpm for alert if any client become source of attack

    Posted Feb 14, 2015 12:49 AM

    Hi All,

    What is the best practise applying on srpm for alert if any client become source of attack, any client spreading worm accross network? please submission your best reporting or alert through mail on SEPM so being a SEPM i can act quick getting alerts?



  • 2.  RE: best practise applying on srpm for alert if any client become source of attack
    Best Answer

    Posted Feb 14, 2015 12:57 AM

    See chetan and others comments

    https://www-secure.symantec.com/connect/forums/brute-force-notification-sepm-1215

     

    Edit

    Best practices articles for Symantec Endpoint Protection (SEP)

    Article:TECH181685  |  Created: 2012-02-17  |  Updated: 2014-10-22  |  Article URL http://www.symantec.com/docs/TECH181685

    Threat remediation

    Troubleshoot and respond to threats that may be on your endpoints.

     



  • 3.  RE: best practise applying on srpm for alert if any client become source of attack

    Posted Feb 14, 2015 07:28 AM
    The alerting is fine but the response is the key. Make sure your operations and security teams get the alerts but do you have an incident response procedure in place? You'll want to get the trouble machines off the network immediately for remediation.