- CheckMates
- :
- Products
- :
- Harmony
- :
- Endpoint
- :
- Endpoint Digest Email
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Endpoint Digest Email
I receive weekly 'digest' emails in the form of a Weekly Security Report from Harmony Endpoint Cloud.
In this weeks report I have an entry that states:
Prevented Zero-Day Phishing Attacks: 1
However, that statistic does not match Infinity Portal reporting which states there are no attacks.
I have run Threat Hunting using the date range and it returns no mention of this event either.
It does however show up in the logs which I assume is where the automated report picked up on it.
Ultimately it's a non-issue but I thought it was odd that the event is mentioned/visible nowhere except the
report and the log.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Curious what the event was that was flagged?
Feel free to post a screenshot with the sensitive details redacted.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sure. It was a ZeroPhishing notification lodged against an internal website.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Actually today I am getting Loading Threat Hunting with a circle spinning for a
long while, then the Threat Hunting panel draws and I see 'No data available for hunting'.
It must be down today. **Update - Looks like there is an issue.
Jun 15, 2023 - 14:17 UTC
Jun 15, 2023 - 13:18 UTC
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It's interesting the log entry is "Detect" rather than "Prevent" which is maybe why Threat Hunting didn't pick it up...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Perhaps more interesting is all settings are on prevent.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Feels like how Anti-Bot used to flag the DNS Trap as "detect" under similar circumstances.
Not 100% sure this is expected, though.
