History of groups involved in an attack?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

History of groups involved in an attack?

L0 Member

Hello,

 

when an attack occurs, where can I find the entire history of groups that where involved in that attack? Can I see that in Wildifre maybe or is it AutoFocus that is needed for that?

 

Thanks.

1 accepted solution

Accepted Solutions

Community Team Member

Hi @jermomiu ,

 

You can manually go through all the logs but that's quite troublesome and time consuming.

 

Autofocus can help you with that. It enables you to easily identify critical attacks, so that you can triage effectively and take action without requiring additional IT resources. It correlates data from WildFire, the PAN-DB URL Filtering database, Unit 42, and from third-party feeds.

 

However, Autofocus is end-of-sale as of September 2022 (but still supported until 2025).

 

For alternatives to Autofocus you might want to look into Cortex XSOAR TIM or AIOps for NGFW

 

Autofocus end-of-sale FAQ and Alternatives 

 

Kind regards,

-Kiwi

 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.

View solution in original post

1 REPLY 1

Community Team Member

Hi @jermomiu ,

 

You can manually go through all the logs but that's quite troublesome and time consuming.

 

Autofocus can help you with that. It enables you to easily identify critical attacks, so that you can triage effectively and take action without requiring additional IT resources. It correlates data from WildFire, the PAN-DB URL Filtering database, Unit 42, and from third-party feeds.

 

However, Autofocus is end-of-sale as of September 2022 (but still supported until 2025).

 

For alternatives to Autofocus you might want to look into Cortex XSOAR TIM or AIOps for NGFW

 

Autofocus end-of-sale FAQ and Alternatives 

 

Kind regards,

-Kiwi

 
LIVEcommunity team member, CISSP
Cheers,
Kiwi
Please help out other users and “Accept as Solution” if a post helps solve your problem !

Read more about how and why to accept solutions.
  • 1 accepted solution
  • 1178 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!