Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
TAEKBOM_Kim
Contributor

URL regular expression in Threat Emulation Exceptions

Hi

I want to make an exception for access to the XXXX.XXX.r.cloudfront.net. 

 

<Event Log>

A-1.JPG

Resource-> http://aldn.altools.co.kr/setup/ALZip1092.exe
Destination-> server-52-85-230-110.icn55.r.cloudfront.net (52.85.230.110)
                         server-13-225-132-39.icn54.r.cloudfront.net (13.225.132.39)
                         server-99-86-144-55.icn51.r.cloudfront.net (99.86.144.55)
                         server-52-85-230-85.icn55.r.cloudfront.net (52.85.230.85)
                         .....
                         ...
                         ..

 

<I did it this way, but I failed to make an exception.>

A-2.JPG

* disabled URLs defined as Regular Expression

 

Anyone knows how to make an exception?

 

0 Kudos
2 Replies
G_W_Albrecht
Legend Legend
Legend

I would not use Regex here because it is not needed - defining a domain .r.cloudfront.net should be enough ! Also see:

White Paper - Implementing Non-FQDN Domain Objects

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
TAEKBOM_Kim
Contributor

I want to make an exception in Threat Prevention. 

Threat Prevention -> Exceptions 

< Global Exceptions >

a-3.JPG

 

I think FQDN is not the right solution here.

Because domain objects are not supported on Threat Prevention Policy.

a-5.JPG

 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events