Hello guys !
We have a use case where we need to sniff traffic in Promiscuous mode on a host protected by HIPS.
However HIPS seems to block that kind of trafic because the destination MAC address doesn't match the host's MAC address.
Allowing bridged traffic won't do the trick either since it only works for MAC addresses used by Virtualization softwares.
Is there any workaround for this that doesn't involve disabling HIPS ? Thanks !
you need to have the firewall disabled if you are getting blocks.