<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: False Positive on logs (Sandblast Agent) on BANKING Sites in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10967#M3431</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe not really very helpfull, but: Current GA Jumbo Take is&amp;nbsp;&lt;SPAN class=""&gt;Take_338 and used Take 143 is from 21. Apr 2016...&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 29 Nov 2018 12:45:44 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2018-11-29T12:45:44Z</dc:date>
    <item>
      <title>False Positive on logs (Sandblast Agent) on BANKING Sites</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10962#M3426</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Team,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="border: 0px; font-weight: bold;"&gt;&lt;STRONG&gt;Setup:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Endpoint Server&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;OS: GAIA R77.30 with 143 hotfix and R77.30 Adds on package installed.&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;Client Package : E80.87&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;SPAN style="border: 0px; font-weight: bold; text-decoration: underline;"&gt;&lt;STRONG&gt;Blade Enabled:&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;1.Sandblast Agent Anti-Ransomware, behavioral guard and Forensics&lt;BR /&gt;2.Sandblast Agent Anti-Bot&lt;BR /&gt;3.Sandblast Agent Threat extraction and emulation&lt;/P&gt;&lt;P style="color: #333333; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;We use TE appliance for extraction and emulation (Local Emulation).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="text-decoration: underline;"&gt;&lt;EM&gt;&lt;STRONG&gt;Scenario :&lt;/STRONG&gt;&lt;/EM&gt;&lt;/SPAN&gt; We visit some banking sites where we able to access the websites and even we see the Sandblast agent extension popup show &lt;STRONG&gt;"Scanned Phishing verified by Zero Phishing"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Some are GOVT websites like IRCTC (railway sites of India)&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Some are BANKING Sites&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="75817" class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/75817_pastedImage_16.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;BUT as we see on logs and find below result.&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;This is completely&amp;nbsp;unbelievable&lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/shocked.png" /&gt;&lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/shocked.png" /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Showing:-&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Severity:03&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Confidence Level: High&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Protection&amp;nbsp;Name: Deceptive site Detection&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Protection Type: Phishing Prevention&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="75818" class="image-3 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/75818_pastedImage_86.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Please&amp;nbsp;HELP me to resolve the issue.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;#Chinmaya Naik (INDIA)&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2018 10:50:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10962#M3426</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2018-11-29T10:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive on logs (Sandblast Agent) on BANKING Sites</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10963#M3427</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, but is do not fully understand the Issue: i read that you can use these sites successfully, but logs show phishing detected ? Or are the sites working no more ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2018 12:11:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10963#M3427</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-11-29T12:11:54Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive on logs (Sandblast Agent) on BANKING Sites</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10964#M3428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am at a loss too. The logs in the screenshot are not those for the website in question. What is the issue, actually?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2018 12:24:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10964#M3428</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-11-29T12:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive on logs (Sandblast Agent) on BANKING Sites</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10965#M3429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear&amp;nbsp;Günther and Valeri,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We able to access the banking sites without any issue but on the logs section, it showing phishing event and description&amp;nbsp;site as banking sites. see the screenshot. (below logs for railway reservation sites)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="75819" class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/75819_pastedImage_3.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG __jive_id="75820" class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/75820_pastedImage_4.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2018 12:37:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10965#M3429</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2018-11-29T12:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive on logs (Sandblast Agent) on BANKING Sites</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10966#M3430</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Open a case with TAC for that, please&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2018 12:43:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10966#M3430</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-11-29T12:43:06Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive on logs (Sandblast Agent) on BANKING Sites</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10967#M3431</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe not really very helpfull, but: Current GA Jumbo Take is&amp;nbsp;&lt;SPAN class=""&gt;Take_338 and used Take 143 is from 21. Apr 2016...&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2018 12:45:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10967#M3431</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-11-29T12:45:44Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive on logs (Sandblast Agent) on BANKING Sites</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10968#M3432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok, I will update the status once I installed the latest jumbo Take_338.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;Günther and Valeri&amp;nbsp;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp; thanks for the suggestion&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2018 13:11:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10968#M3432</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2018-11-29T13:11:59Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive on logs (Sandblast Agent) on BANKING Sites</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10969#M3433</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please keep us posted here about the results&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Nov 2018 13:32:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10969#M3433</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-11-29T13:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive on logs (Sandblast Agent) on BANKING Sites</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10970#M3434</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;Yes sure I will update&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or else do you think that &amp;nbsp;upgrade to R80.20 is resolve the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2018 04:48:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10970#M3434</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2018-11-30T04:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive on logs (Sandblast Agent) on BANKING Sites</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10971#M3435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would start with a&amp;nbsp;small step and install the newer Jumbo Take first &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2018 08:40:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10971#M3435</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-11-30T08:40:18Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive on logs (Sandblast Agent) on BANKING Sites</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10972#M3436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue is a known bug in E80.87 and E80.88 in which the wrong log is sent in the case a potential phishing site was found to be benign.&lt;/P&gt;&lt;P&gt;The issue is fixed in E80.89 which will be released soon.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As a workaround, you can change the policy and disable the "Send log on each scanned site" on the Zero Phishing Settings. By that, logs will be sent only for sites that were found malicious, and this confusion will be avoided.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="Here" s="" the="" policy="" to="" disable="" log="" for="" every="" scanned="" site="" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for the inconvenience,,,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gal.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Nov 2018 09:27:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10972#M3436</guid>
      <dc:creator>Gal_Carmeli</dc:creator>
      <dc:date>2018-11-30T09:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: False Positive on logs (Sandblast Agent) on BANKING Sites</title>
      <link>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10973#M3437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you so much Gal&amp;nbsp; for this information&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We will wait for the next E80.89 package and will update the status as well its work for us or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&amp;nbsp;&lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2018 16:24:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/False-Positive-on-logs-Sandblast-Agent-on-BANKING-Sites/m-p/10973#M3437</guid>
      <dc:creator>Chinmaya_Naik</dc:creator>
      <dc:date>2018-12-05T16:24:49Z</dc:date>
    </item>
  </channel>
</rss>

