<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Best way to alert Checkpoint of probable FPs? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Best-way-to-alert-Checkpoint-of-probable-FPs/m-p/25478#M5146</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A TAC case is always your best bet in the case of a false positive.&lt;/P&gt;&lt;P&gt;I'll see what I can find out from our Threat Operations team, though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 09 Sep 2018 21:52:46 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-09-09T21:52:46Z</dc:date>
    <item>
      <title>Best way to alert Checkpoint of probable FPs?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-way-to-alert-Checkpoint-of-probable-FPs/m-p/25477#M5145</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Checkpoint IPS has recently (09-08-2018) started erroneously tagging many domains ending in akamaiedge.net as malicious (Phishing_website.upvi) which is creating very large amounts of FP alerts. Here are some examples:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;e11696.dscg.akamaiedge.net&lt;/P&gt;&lt;P&gt;e16595.dsca.akamaiedge.net&lt;/P&gt;&lt;P&gt;e912.f.akamaiedge.net&lt;/P&gt;&lt;P&gt;e6640.g.akamaiedge.net&lt;/P&gt;&lt;P&gt;.. etc&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully someone at Checkpoint reviews this post and fixes the issue ASAP. Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Sep 2018 12:54:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-way-to-alert-Checkpoint-of-probable-FPs/m-p/25477#M5145</guid>
      <dc:creator>Fred_Joans</dc:creator>
      <dc:date>2018-09-09T12:54:59Z</dc:date>
    </item>
    <item>
      <title>Re: Best way to alert Checkpoint of probable FPs?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-way-to-alert-Checkpoint-of-probable-FPs/m-p/25478#M5146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A TAC case is always your best bet in the case of a false positive.&lt;/P&gt;&lt;P&gt;I'll see what I can find out from our Threat Operations team, though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 09 Sep 2018 21:52:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-way-to-alert-Checkpoint-of-probable-FPs/m-p/25478#M5146</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-09T21:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: Best way to alert Checkpoint of probable FPs?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-way-to-alert-Checkpoint-of-probable-FPs/m-p/25479#M5147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I also encountered a similar problem (&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;09-sept-2018 - 10&lt;SPAN&gt;-sept-2018)&lt;/SPAN&gt;&lt;/SPAN&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2018 11:15:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-way-to-alert-Checkpoint-of-probable-FPs/m-p/25479#M5147</guid>
      <dc:creator>MK9</dc:creator>
      <dc:date>2018-09-12T11:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Best way to alert Checkpoint of probable FPs?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-way-to-alert-Checkpoint-of-probable-FPs/m-p/25480#M5148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The false positive should have already been addressed by now, assuming you have installed the latest IPS signatures.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2018 18:50:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-way-to-alert-Checkpoint-of-probable-FPs/m-p/25480#M5148</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-12T18:50:17Z</dc:date>
    </item>
    <item>
      <title>Re: Best way to alert Checkpoint of probable FPs?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Best-way-to-alert-Checkpoint-of-probable-FPs/m-p/25481#M5149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Problem is solved:)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 18 Sep 2018 19:52:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Best-way-to-alert-Checkpoint-of-probable-FPs/m-p/25481#M5149</guid>
      <dc:creator>MK9</dc:creator>
      <dc:date>2018-09-18T19:52:02Z</dc:date>
    </item>
  </channel>
</rss>

