- CheckMates
- :
- Products
- :
- Quantum
- :
- Threat Prevention
- :
- Re: Detect Client's App or Service Request To Mali...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Detect Client's App or Service Request To Malicious Website
Dear All,
I have one concern from my client as they tracked on SmartTracker and SmartEvent and see some traffics from client to malicious URL in the network. And we want to know which application or which service are performing this action? So any idea or recommend on Checkpoint firewall or endpoint protection that we can see kind of this log? As on SmartEvent or SmartTracker we saw only source and malicious URL.
Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are you running SandBlast Agent on the Endpoint?
If so it would be possible to run a forensics report to see what on the Endpoint reached out.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello Dameon,
Thanks for your reply. Actually, we don't have SandBlast Agent on endpoint. I just looking for any way that we can show on Checkpoint firewall based on our current environment of Threat Prevention or on SmartEvent.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Unless you had an agent on the endpoint tracking what process issued what request, how would the gateway or the management know?
Also, how would an on-premise gateway protect an endpoint when it is outside your corporate perimeter?
This is why we offer SandBlast Agent (among other solutions) and they are meant to work together.
