Endpoint Protection

 View Only
  • 1.  Symantec.cloud Alerts [alerts@spn.com Reports

    Posted Oct 13, 2014 11:16 AM

    A high-risk intrusion was detected on COMPUTERXXX.domain within group XXXYYY on 10/13/2014 11:10:09 AM.

    Intrusion Name

    >>>> Please add to Report....
    Attacker Computer

    89.136.120.205 0

    >>>> end Addition

    Targeted Application

    Targeted IP
    192.168.10.xxx

    Targeted Port Number
    0

    Targeted Host Name

    Status
    Blocked



  • 2.  RE: Symantec.cloud Alerts [alerts@spn.com Reports

    Posted Oct 13, 2014 11:18 AM

    IPS blocked an attack. What is the concern?



  • 3.  RE: Symantec.cloud Alerts [alerts@spn.com Reports

    Posted Oct 13, 2014 03:21 PM
    The report that we receive does not contain the attacker ip address. This is very usefull to investigate who is attacking Thetefore our request to add this information to the mail report as showed in ny primary request. Greetings Leo


  • 4.  RE: Symantec.cloud Alerts [alerts@spn.com Reports

    Posted Oct 13, 2014 04:47 PM

    How to Submit a Suggestion or Idea for Symantec Products.
    http://www.symantec.com/docs/HOWTO38237