attacker and victim who is impacted?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

attacker and victim who is impacted?

Cyber Elite
Cyber Elite

under threat logs i see attacker and victim and also i see spyware signature

 

attacker is source -  dns server---

 

victim is --  appliance 

 

how can i verify who is impacted with this spyware?

 

Mike

MP

Help the community: Like helpful comments and mark solutions.
1 accepted solution

Accepted Solutions

Hello,

The Victim IP isthe device that is impacted by that log entry. Not sure if you mean something else?

 

Regards,

View solution in original post

4 REPLIES 4

Cyber Elite
Cyber Elite

Hello,

There should be a threatid, do a pivot search for it and it should show all the times it has been hit with the additional info. In the coulumn drop down its just labled as ID. But that would be what to pivot your seach on.

 

You can also take that threatid and search for it on PAN's site, ThreatDB and get more info on it.

https://threatvault.paloaltonetworks.com/

 

Hope that helps.

 

i already gone through detailed traffic logs and threat ID.

But i could   not figure out which device is impacted?

 

 

how can i figure out which device is impacted?

 

 

MP

Help the community: Like helpful comments and mark solutions.

Hello,

The Victim IP isthe device that is impacted by that log entry. Not sure if you mean something else?

 

Regards,

Many thanks for confirming that.

MP

Help the community: Like helpful comments and mark solutions.
  • 1 accepted solution
  • 2630 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!