- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi,
I got this log:
The pcap file in its payload shows something like this:
l v|’|’|V HJvamFuX
0M0NkY2RTk=|’|’|MARK|’|’|user|’|’|2013-11-22|’|’|W
in XP|’|’|No|’|’|0.6.4|’|’|..|’|’|[endof]
Autonomous Threat Prevention is configured with Perimeter protection profile
I wonder why is that "Detect" not "Blocked"? does that count as a successful hack!?
Confidence Level of the protection has a 'low' rating best to follow-up with TAC / IRT as appropriate.
any way to block
Backdoor.MSIL.Jaktinier.D
Yes:
Use the Optimized profile and check the General Policy pane > Activation Mode section, and see if all Confidence levels are set to Prevent. In your case, Confidence level is low, so following the profile settings it will detect only (as it is not sure at all if this really is the bot in question). I suggest to set all Confidence levels to Prevent except low (do nothing then as detect will cost as much resources as Prevent but only log it)
The protection to block this has a low confidence rating so excepting low is contrary to the need here?
Seems this is configured as Detect for low confidence - something i suggest to avoid, either set it to protect or to do nothing.
It should give you more options if you click on "remediation options" from the log I believe.
Andy
Difficult to advise on this in depth without knowing the environment in greater detail
Custom TP profile / policy is likely needed for instance if you were trying to alter the 'low confidence' treatment..
Confidence levels are the same across all threat prevention blades:
A detect is expected behaviour for this perimeter profile:
Please see top left.
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY