- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: solarwinds ips logs query
Options
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×
Sign in with your Check Point UserCenter/PartnerMap account to access more great content and get a chance to win some Apple AirPods! If you don't have an account, create one now for free!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
solarwinds ips logs query
So is it possible to see the Mitre attack techniques on the ips logs seen here in this link posted on the official department of homeland security website?
https://attack.mitre.org/tactics/TA0003/
if i filter by ips logs with the ip of the solarwinds server will i see anything related to those mitre attacks? assuming those attacks happen (i have looked at ips logs for last 3 months and i do not see anything out of the ordinary).
Thank you.
1 Reply
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We actually see it on other blades as well.
Please check the following SK: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
