Decoy files false-positives?
Eddy77
Newbie ✭
We are using CC behind a TZ370 with Firewall enforcement and network alerts setup.
On several network clients we get Firewall alerts on IPS/BAD-FILES:
After further investigation on the Firewall I managed to pull the responder IP addresses: 3.220.221.104, 35.173.44.173, 54.172.195.97
The IP addresses belong to "sonicwall.sentinelone.net"
We have the decoy files function enabled in CC, could this be CC trying to download decoy files?
Category: Capture Security Center
Tagged:
0
Comments
I created a support ticket for this issue, they recommended me to disable the Decoy files in the CC policy to check it the Decoy files are triggering IPS. After disabling the Decoy files option I still got the IPS-alerts and ended up to add sonicwall.sentinelone.net as IPS exclusion. After that the alerts where gone.
So it must be some other file/exe that is triggering IPS, probably sentinelone agent updates :-)