attacker and victim who is impacted?

Reply
Highlighted
Cyber Elite

attacker and victim who is impacted?

under threat logs i see attacker and victim and also i see spyware signature

 

attacker is source -  dns server---

 

victim is --  appliance 

 

how can i verify who is impacted with this spyware?

 

Mike

MP

Accepted Solutions
Highlighted
Cyber Elite

Hello,

The Victim IP isthe device that is impacted by that log entry. Not sure if you mean something else?

 

Regards,

View solution in original post


All Replies
Highlighted
Cyber Elite

Hello,

There should be a threatid, do a pivot search for it and it should show all the times it has been hit with the additional info. In the coulumn drop down its just labled as ID. But that would be what to pivot your seach on.

 

You can also take that threatid and search for it on PAN's site, ThreatDB and get more info on it.

https://threatvault.paloaltonetworks.com/

 

Hope that helps.

 

Highlighted
Cyber Elite

i already gone through detailed traffic logs and threat ID.

But i could   not figure out which device is impacted?

 

 

how can i figure out which device is impacted?

 

 

MP
Highlighted
Cyber Elite

Hello,

The Victim IP isthe device that is impacted by that log entry. Not sure if you mean something else?

 

Regards,

View solution in original post

Highlighted
Cyber Elite

Many thanks for confirming that.

MP
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!