Yes it would be most helpful, I agree... unfortunately I can't and I know my network firewall won't show me that information. I'm working with our SOC vendor as well but figured I'd reach out to you regarding this since I felt it could be rogue related. I would agree that if it were a malware issue I'd see the traffic every day, or at least on a scheduled time period based on typical c2 bot behavior.
Let me check with a peer advanced member to see if they have seen any of that behavior with rsd. I will get back with you.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
one quick question - in your original post you said that the sensor was updated. Updated how specifically?
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
I don't know how, I'm pretty sure it's config'd to update automatically. I monitor the rogues from a security and investigations standpoint, but don't administer the system itself. I can only see in the ePolicy Orchestrator when the RSD "install" action type occurred.
Ok, got it.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Good morning, are there any updates on information you may have been able to find regarding this? Thanks!
We have not seen an internal sensor do any type port scans on any external systems. If there is any way possible to capture a packet capture of that traffic, we can track it down, but without it, there isn't much we can prove or disprove either way.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA