Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
gander
Explorer

Access to infected resources before signature is created

Hello,

What is the proper way to manage infections occurring because no signature have yet been created and sandbox didn't block it?

In my sense, there should be a way to analyze previous access with newly created signatures and generate alerts

 

0 Kudos
2 Replies
PhoneBoy
Admin
Admin

Signatures require traffic to match against, which you obviously won't have after the fact.
The only thing you might have are IPs and URLs accessed, which could theoretically be "re-analyzed" after the fact.
Our XDR offering includes some additional tools that may be useful in such situations: https://www.checkpoint.com/horizon/xdr-xpr/ 

the_rock
Legend
Legend

I see what Phoneboy is saying. I watched presentation Sales gave about XDR and it definitely could help here.

Best regards,

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events