within the NSM there a botnet function.
All I see is that you can download this version and apply it to the sensors. Not like regarding signatures, I have not found any information what this exactly is, or if there are any signatures included. I have searched the KC but have not found any information what exactly it is.
Has someone more information on this?
+ what are the signatures
+ how do they work
+ where can I see what brings a nwe version, before updating it
The best way to learn about the botnet detection capability of the Network Security Platform is to review Chapter 16 (Advanced Botnet Detection) of the McAfee Network Security Platform 8.2 IPS Administration Guide.
Technical Support Engineer
McAfee. Part of Intel Security.