<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Manage goto meeting / webex downloads in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Manage-goto-meeting-webex-downloads/m-p/23455#M3597</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do you manage the different meeting systems download apps?&lt;/P&gt;&lt;P&gt;Sndblast keep alerting in logs as detected but with Severity=Low and Confidence Level=N/A&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SandBlast Agent Threat Emulation has detected access to: C:\Users\USERNAME\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XXUF8VS0\&lt;STRONG&gt;G2MCoreInstExtractor[1].exe&lt;/STRONG&gt;. See attached report&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am thinking of changing the "Blade Activition" policy setting for the Anti-Bot agent to ignore Confidence Level=Low. Today it is detect on Low and prevent on High and Medium.&lt;/P&gt;&lt;P&gt;Is a change like that safe, or is it better to keep it as is an filter the events, logs and reports?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 May 2018 13:57:12 GMT</pubDate>
    <dc:creator>Mikael_Bygren</dc:creator>
    <dc:date>2018-05-11T13:57:12Z</dc:date>
    <item>
      <title>Manage goto meeting / webex downloads</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Manage-goto-meeting-webex-downloads/m-p/23455#M3597</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do you manage the different meeting systems download apps?&lt;/P&gt;&lt;P&gt;Sndblast keep alerting in logs as detected but with Severity=Low and Confidence Level=N/A&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SandBlast Agent Threat Emulation has detected access to: C:\Users\USERNAME\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XXUF8VS0\&lt;STRONG&gt;G2MCoreInstExtractor[1].exe&lt;/STRONG&gt;. See attached report&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am thinking of changing the "Blade Activition" policy setting for the Anti-Bot agent to ignore Confidence Level=Low. Today it is detect on Low and prevent on High and Medium.&lt;/P&gt;&lt;P&gt;Is a change like that safe, or is it better to keep it as is an filter the events, logs and reports?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2018 13:57:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Manage-goto-meeting-webex-downloads/m-p/23455#M3597</guid>
      <dc:creator>Mikael_Bygren</dc:creator>
      <dc:date>2018-05-11T13:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Manage goto meeting / webex downloads</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Manage-goto-meeting-webex-downloads/m-p/23456#M3598</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would keep it as a filter versus not logging Low Confidence triggers.&lt;/P&gt;&lt;P&gt;Low Confidence events could lead to higher confidence ones later on.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2018 15:36:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Manage-goto-meeting-webex-downloads/m-p/23456#M3598</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-05-11T15:36:48Z</dc:date>
    </item>
  </channel>
</rss>

