<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic using IPS engine for replaying older traffic in Off Topic</title>
    <link>https://community.checkpoint.com/t5/Off-Topic/using-IPS-engine-for-replaying-older-traffic/m-p/160688#M121</link>
    <description>&lt;P&gt;My security team wants to be able to replay traffic (I don't know how they would) from the past to see what got thru before Check Point started preventing traffic.&amp;nbsp; For damage control and auditing.&amp;nbsp; &amp;nbsp;I responded that we have logs, we don't have the traffic.&amp;nbsp; But I am curious RE: forensics how teams go back and look for damage even a month before detection.&lt;/P&gt;
&lt;P&gt;Also, this question came up because they want to look for clues in old logs.&amp;nbsp; Does Check Point show what they are checking for pattern management detection?&amp;nbsp; I assume no - it's proprietary like the KFC recipe.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 28 Oct 2022 15:32:54 GMT</pubDate>
    <dc:creator>Daniel_Kavan</dc:creator>
    <dc:date>2022-10-28T15:32:54Z</dc:date>
    <item>
      <title>using IPS engine for replaying older traffic</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/using-IPS-engine-for-replaying-older-traffic/m-p/160688#M121</link>
      <description>&lt;P&gt;My security team wants to be able to replay traffic (I don't know how they would) from the past to see what got thru before Check Point started preventing traffic.&amp;nbsp; For damage control and auditing.&amp;nbsp; &amp;nbsp;I responded that we have logs, we don't have the traffic.&amp;nbsp; But I am curious RE: forensics how teams go back and look for damage even a month before detection.&lt;/P&gt;
&lt;P&gt;Also, this question came up because they want to look for clues in old logs.&amp;nbsp; Does Check Point show what they are checking for pattern management detection?&amp;nbsp; I assume no - it's proprietary like the KFC recipe.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Oct 2022 15:32:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/using-IPS-engine-for-replaying-older-traffic/m-p/160688#M121</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2022-10-28T15:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: using IPS engine for replaying older traffic</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/using-IPS-engine-for-replaying-older-traffic/m-p/160719#M122</link>
      <description>&lt;P&gt;Replaying traffic in a lab environment is one thing but as you say where is the traffic capture coming from as we don't blindly store it?&lt;/P&gt;
&lt;P&gt;Refer: tcpreplay tool&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Horizon NDR might be something the team is interested in investigating further.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Oct 2022 01:41:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/using-IPS-engine-for-replaying-older-traffic/m-p/160719#M122</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-10-29T01:41:45Z</dc:date>
    </item>
  </channel>
</rss>

