My customer would like to see only CnC threats after the filtering.
So I think to use the filtering for spyware category.
But there are only 'any' and 'unknown' in threat logs.
I want to use the each spyware category such as botnet , backdoor and etc.
How should I do?
From the Threat database selected from the custom reports we can set the filters such that we are looking for type "Spyware" and filter all the spyware threat logs.
The allowed Threat types are flood, scan, spyware, virus, vulnerability.
So if we are looking for anything outside these then we have to go for predefined reports as pointed earlier by hyadavalli where we can find the botnet and other reports.
Thank you for the answser, hyadavalli , Phoenix and panos.
As panos mentioned, I think so too.
I can not filter each spyware category in threat logs or custom report.
But I have gotten some idea for filtering command and control, recently.
I read the spyware phone home detection value of threat id fields are between 10000 ~ 19999 in the integration syslog document.
So I will make the filtering as below in threat logs.
(threatid geq 10000) and (threatid leq 19999)
How do you think about it?
Do you have any idea better than it?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!