Hi @Spooky10111,
Thank you for your post. This is a behavior by design for NIPS signature based detection and should not be taken as a false positive.
Hi @AdithyanT
I have both network addresses which both have TP and ATP but the ports fields are blank, how would I go about investigating these events
Kind Regards
Lesiba Sephoka
Hi @Spooky10111,
Thank you for your response. You can refer to a similar post in community that talks about the same detection:
https://community.mcafee.com/t5/Endpoint-Security-ENS/Rule-ID-Reference/td-p/643325
Essentially, This detection is to do with the source IP trying to send a malicious request and hence your machine, being the target with ENS installed, is blocking it as it should. Any investigation on this matter should be carried against the source IP. if the source does not belong to your network, I would recommend blocking it from your Gateway Firewall.
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA