<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to detect the virus came from which ip in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/how-to-detect-the-virus-came-from-which-ip/m-p/243532#M478</link>
    <description>&lt;P&gt;If you've implemented DNS sinkhole Anti-Spyware protection in your firewall, hosts attempting to hit the sinkhole IP would be those trying to communicate&amp;nbsp;through command-and-control, so it can help pinpoint the infections. You can also look for entries in the Threat logs for Anti-spyware signatures (that are not DNS based) to see if you can spot any malicious activity.&lt;/P&gt;
&lt;P&gt;If you have Traps and Magnifier, you may also be able to detect behavioral anomalies which can help pinpoint the infected hosts.&lt;/P&gt;</description>
    <pubDate>Mon, 17 Dec 2018 18:18:32 GMT</pubDate>
    <dc:creator>mivaldi</dc:creator>
    <dc:date>2018-12-17T18:18:32Z</dc:date>
    <item>
      <title>How to detect the virus came from which ip</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/how-to-detect-the-virus-came-from-which-ip/m-p/243472#M477</link>
      <description>&lt;P&gt;several servers in Data Center are affected by a virus but I am unable to pin point the source. Can anyone assist?&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 12:03:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/how-to-detect-the-virus-came-from-which-ip/m-p/243472#M477</guid>
      <dc:creator>Admin_Network</dc:creator>
      <dc:date>2018-12-17T12:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to detect the virus came from which ip</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/how-to-detect-the-virus-came-from-which-ip/m-p/243532#M478</link>
      <description>&lt;P&gt;If you've implemented DNS sinkhole Anti-Spyware protection in your firewall, hosts attempting to hit the sinkhole IP would be those trying to communicate&amp;nbsp;through command-and-control, so it can help pinpoint the infections. You can also look for entries in the Threat logs for Anti-spyware signatures (that are not DNS based) to see if you can spot any malicious activity.&lt;/P&gt;
&lt;P&gt;If you have Traps and Magnifier, you may also be able to detect behavioral anomalies which can help pinpoint the infected hosts.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Dec 2018 18:18:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/how-to-detect-the-virus-came-from-which-ip/m-p/243532#M478</guid>
      <dc:creator>mivaldi</dc:creator>
      <dc:date>2018-12-17T18:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to detect the virus came from which ip</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/how-to-detect-the-virus-came-from-which-ip/m-p/303756#M711</link>
      <description>&lt;P&gt;Did you find that something on threat logs?&lt;/P&gt;</description>
      <pubDate>Sat, 14 Dec 2019 19:39:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/how-to-detect-the-virus-came-from-which-ip/m-p/303756#M711</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-12-14T19:39:06Z</dc:date>
    </item>
  </channel>
</rss>

