<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SandBlast Agent Anti-Bot exception in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Anti-Bot-exception/m-p/27251#M3607</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are there any official recommendations from Check Point on adding exceptions to the SBA Anti-Bot blade?&lt;BR /&gt;For example, we have the Anti-Bot blade&amp;nbsp;incident when the user accesses the UserCheck of Application Control blade. How to explain this behavior for customer?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 May 2018 13:26:56 GMT</pubDate>
    <dc:creator>Olga_Kuts</dc:creator>
    <dc:date>2018-05-30T13:26:56Z</dc:date>
    <item>
      <title>SandBlast Agent Anti-Bot exception</title>
      <link>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Anti-Bot-exception/m-p/27251#M3607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are there any official recommendations from Check Point on adding exceptions to the SBA Anti-Bot blade?&lt;BR /&gt;For example, we have the Anti-Bot blade&amp;nbsp;incident when the user accesses the UserCheck of Application Control blade. How to explain this behavior for customer?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 May 2018 13:26:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Anti-Bot-exception/m-p/27251#M3607</guid>
      <dc:creator>Olga_Kuts</dc:creator>
      <dc:date>2018-05-30T13:26:56Z</dc:date>
    </item>
    <item>
      <title>Re: SandBlast Agent Anti-Bot exception</title>
      <link>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Anti-Bot-exception/m-p/27252#M3608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure if there are any official recommendations, but you can exclude different types of things for Anti-Bot.&amp;nbsp;&amp;nbsp;If there is a specific process (such as a development application) that keeps triggering Anti-Bot because its trying to go out somewhere legitimately, you can try to exclude that process.&amp;nbsp; We have some of our internal domains excluded for that reason.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/66751_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jun 2018 20:06:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Anti-Bot-exception/m-p/27252#M3608</guid>
      <dc:creator>Steve_Lander</dc:creator>
      <dc:date>2018-06-26T20:06:46Z</dc:date>
    </item>
    <item>
      <title>Re: SandBlast Agent Anti-Bot exception</title>
      <link>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Anti-Bot-exception/m-p/27253#M3609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="direction: ltr;"&gt;&lt;SPAN style="color: black;"&gt;Hi Olha,&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="direction: ltr;"&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="direction: ltr;"&gt;&lt;SPAN style="color: #000000;"&gt;There are no recommendations for exceptions.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="direction: ltr;"&gt;Analyzing your logs, a "Trojan.Win32.Ponmocup.I" bot was found by AntiBot.&lt;/P&gt;&lt;P style="direction: ltr;"&gt;&lt;SPAN style="color: #000000;"&gt;The URL used&lt;/SPAN&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp;is related to User check simple configuration in Smart dashboard which is configured by the user, hence may contain&amp;nbsp;links which are recognized as malicious.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="direction: ltr;"&gt;&lt;/P&gt;&lt;P style="direction: ltr;"&gt;I suggest to replace it.&lt;/P&gt;&lt;P style="direction: ltr;"&gt;A ticket can be opened to TAC team for additional assistance with this issue.&lt;/P&gt;&lt;P style="direction: ltr;"&gt;&lt;SPAN style="color: #000000;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="direction: ltr;"&gt;Regards,&lt;/P&gt;&lt;P style="direction: ltr;"&gt;Doron Zuckerman&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Jul 2018 06:35:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/SandBlast-Agent-Anti-Bot-exception/m-p/27253#M3609</guid>
      <dc:creator>Doron_Zuckerman</dc:creator>
      <dc:date>2018-07-02T06:35:55Z</dc:date>
    </item>
  </channel>
</rss>

