Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Olga_Kuts
Advisor

SandBlast Agent Anti-Bot exception

Are there any official recommendations from Check Point on adding exceptions to the SBA Anti-Bot blade?
For example, we have the Anti-Bot blade incident when the user accesses the UserCheck of Application Control blade. How to explain this behavior for customer?

2 Replies
Steve_Lander
Collaborator

Not sure if there are any official recommendations, but you can exclude different types of things for Anti-Bot.  If there is a specific process (such as a development application) that keeps triggering Anti-Bot because its trying to go out somewhere legitimately, you can try to exclude that process.  We have some of our internal domains excluded for that reason.  

Doron_Zuckerman
Employee
Employee

Hi Olha,

 

There are no recommendations for exceptions.

Analyzing your logs, a "Trojan.Win32.Ponmocup.I" bot was found by AntiBot.

The URL used is related to User check simple configuration in Smart dashboard which is configured by the user, hence may contain links which are recognized as malicious.

I suggest to replace it.

A ticket can be opened to TAC team for additional assistance with this issue.

 

Regards,

Doron Zuckerman

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events