<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Zero Phishing is set to Prevent mode but Detect in logs in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215056#M8736</link>
    <description>&lt;P&gt;Hi everyone!&lt;/P&gt;&lt;P&gt;Can someone please help me, I'm just wondering why in the logs the action for Zero Phishing blade is Detect. But upon checking the policy, it is set to Prevent mode. See attached screenshots.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Logs Detect.png" style="width: 204px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25844i35E2E67F0EDCB73B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Logs Detect.png" alt="Logs Detect.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policy Prevent.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25843iC1865F604A9D8E64/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Policy Prevent.png" alt="Policy Prevent.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Why is it different? It should be Prevent in the logs as well right? Does anyone of you experienced this or am I missing out on something? Kind of a newbie in HEP &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 23 May 2024 03:22:19 GMT</pubDate>
    <dc:creator>62742738</dc:creator>
    <dc:date>2024-05-23T03:22:19Z</dc:date>
    <item>
      <title>Zero Phishing is set to Prevent mode but Detect in logs</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215056#M8736</link>
      <description>&lt;P&gt;Hi everyone!&lt;/P&gt;&lt;P&gt;Can someone please help me, I'm just wondering why in the logs the action for Zero Phishing blade is Detect. But upon checking the policy, it is set to Prevent mode. See attached screenshots.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Logs Detect.png" style="width: 204px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25844i35E2E67F0EDCB73B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Logs Detect.png" alt="Logs Detect.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Policy Prevent.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25843iC1865F604A9D8E64/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Policy Prevent.png" alt="Policy Prevent.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Why is it different? It should be Prevent in the logs as well right? Does anyone of you experienced this or am I missing out on something? Kind of a newbie in HEP &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 03:22:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215056#M8736</guid>
      <dc:creator>62742738</dc:creator>
      <dc:date>2024-05-23T03:22:19Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Phishing is set to Prevent mode but Detect in logs</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215059#M8738</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;
&lt;P&gt;Are all your rules set to prevent for zero phishing and password reuse?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you start with HEP the default policy is set to Detect, is it possible that on of the rules is still in detect mode?&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 04:09:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215059#M8738</guid>
      <dc:creator>AdiGH</dc:creator>
      <dc:date>2024-05-23T04:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Phishing is set to Prevent mode but Detect in logs</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215060#M8739</link>
      <description>&lt;P&gt;Yes, it is all in prevent mode. Even the default one is changed to Prevent mode.&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 04:39:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215060#M8739</guid>
      <dc:creator>62742738</dc:creator>
      <dc:date>2024-05-23T04:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Phishing is set to Prevent mode but Detect in logs</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215063#M8740</link>
      <description>&lt;P&gt;I would do quick remote with TAC, Im sure something rudimentary is missing.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 05:38:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215063#M8740</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-05-23T05:38:11Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Phishing is set to Prevent mode but Detect in logs</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215086#M8741</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;I checked that my policy is prevented and shows detect for sites with http&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="phishing2.png" style="width: 887px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25847i73FFAF05B31A3B9C/image-size/large?v=v2&amp;amp;px=999" role="button" title="phishing2.png" alt="phishing2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="phishing3.png" style="width: 486px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25848i899333EFF140944D/image-size/large?v=v2&amp;amp;px=999" role="button" title="phishing3.png" alt="phishing3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;All these alerts are http related&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="phishing4.png" style="width: 903px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/25849i8BFB88EBE1866322/image-size/large?v=v2&amp;amp;px=999" role="button" title="phishing4.png" alt="phishing4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;All policies are in preventive mode&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 12:12:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215086#M8741</guid>
      <dc:creator>lluner</dc:creator>
      <dc:date>2024-05-23T12:12:45Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Phishing is set to Prevent mode but Detect in logs</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215087#M8742</link>
      <description>&lt;P&gt;Any exclusions configured?&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 12:21:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215087#M8742</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-05-23T12:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Phishing is set to Prevent mode but Detect in logs</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215088#M8743</link>
      <description>&lt;P&gt;Hi , Cris&lt;/P&gt;&lt;PRE&gt;&lt;SPAN class=""&gt;For these sites no&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 12:26:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215088#M8743</guid>
      <dc:creator>lluner</dc:creator>
      <dc:date>2024-05-23T12:26:26Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Phishing is set to Prevent mode but Detect in logs</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215092#M8744</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Those are detect events for sites that were scanned by Zero Phishing. The extension did not recognize them as phishing (which means that the login to them were not prevented) but they were detected to be suspicious because they are http sites with login page.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 13:08:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215092#M8744</guid>
      <dc:creator>andreyta</dc:creator>
      <dc:date>2024-05-23T13:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: Zero Phishing is set to Prevent mode but Detect in logs</title>
      <link>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215093#M8745</link>
      <description>&lt;P&gt;tks.&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/58770"&gt;@andreyta&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 May 2024 13:17:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/Zero-Phishing-is-set-to-Prevent-mode-but-Detect-in-logs/m-p/215093#M8745</guid>
      <dc:creator>lluner</dc:creator>
      <dc:date>2024-05-23T13:17:31Z</dc:date>
    </item>
  </channel>
</rss>

