- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
I am seeing :
but am having trouble verifying the validity of these events.
No RBLs, including IBM X-Force exchange list the resolved IP as a C&C.
Is there a way to determine how CP decided that this host belongs to the Maze C&C?
My Watchtower app is getting hammered with alarms, but the two internal hosts that are being flagged are unlikely to really be compromised.
Just dropped you an email.
Thank you.
It is right there in the logs. There is a DNS request for C&C IP address.
These hosts you are talking about, are they your internal DNS servers? If they are, the infection can be somewhere else. Start DNS logging on those servers to see which machines request DNS entries for C&C
I know the destination and I have doubts about validity of it is being a part of the C&C.
In this case, raise this with TAC.
So this ended-up a false-positive by IRT and was that way for around 24 hours.
Is there any way to address these issues in real-time?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 18 | |
| 12 | |
| 9 | |
| 8 | |
| 4 | |
| 4 | |
| 3 | |
| 3 | |
| 2 | |
| 2 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY