- CheckMates
- :
- Products
- :
- Harmony
- :
- Endpoint
- :
- SandBlast Agent Anti-Bot exception
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
SandBlast Agent Anti-Bot exception
Are there any official recommendations from Check Point on adding exceptions to the SBA Anti-Bot blade?
For example, we have the Anti-Bot blade incident when the user accesses the UserCheck of Application Control blade. How to explain this behavior for customer?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Not sure if there are any official recommendations, but you can exclude different types of things for Anti-Bot. If there is a specific process (such as a development application) that keeps triggering Anti-Bot because its trying to go out somewhere legitimately, you can try to exclude that process. We have some of our internal domains excluded for that reason.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Olha,
There are no recommendations for exceptions.
Analyzing your logs, a "Trojan.Win32.Ponmocup.I" bot was found by AntiBot.
The URL used is related to User check simple configuration in Smart dashboard which is configured by the user, hence may contain links which are recognized as malicious.
I suggest to replace it.
A ticket can be opened to TAC team for additional assistance with this issue.
Regards,
Doron Zuckerman