- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
10-08-2018 11:10 AM
under threat logs i see attacker and victim and also i see spyware signature
attacker is source - dns server---
victim is -- appliance
how can i verify who is impacted with this spyware?
Mike
10-09-2018 01:59 PM
Hello,
The Victim IP isthe device that is impacted by that log entry. Not sure if you mean something else?
Regards,
10-08-2018 11:58 AM
Hello,
There should be a threatid, do a pivot search for it and it should show all the times it has been hit with the additional info. In the coulumn drop down its just labled as ID. But that would be what to pivot your seach on.
You can also take that threatid and search for it on PAN's site, ThreatDB and get more info on it.
https://threatvault.paloaltonetworks.com/
Hope that helps.
10-08-2018 07:09 PM
i already gone through detailed traffic logs and threat ID.
But i could not figure out which device is impacted?
how can i figure out which device is impacted?
10-09-2018 01:59 PM
Hello,
The Victim IP isthe device that is impacted by that log entry. Not sure if you mean something else?
Regards,
10-09-2018 02:48 PM
Many thanks for confirming that.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!