We would like to find out what cause this signature “Microsoft Windows File Manager Remote Code Execution (MS16-130: CVE-2016-7212)” to trigger in Checkpoint IPS.
From the Checkpoint logs, it appears as inbound traffic.
But from the downloaded packet capture, it is reflected the other way round.
Which traffic is triggering this alert?
We have enabled HTTPS Inspection but seems like the packet capture is still encrypted.
Do let us know if we are still lacking of any information to aid in the investigation and we will try to provide.