cancel
Showing results for 
Search instead for 
Did you mean: 

Re: Rogue Sensor calling external IPs

Yes it would be most helpful, I agree... unfortunately I can't and I know my network firewall won't show me that information.  I'm working with our SOC vendor as well but figured I'd reach out to you regarding this since I felt it could be rogue related.  I would agree that if it were a malware issue I'd see the traffic every day, or at least on a scheduled time period based on typical c2 bot behavior.

McAfee Employee cdinet
McAfee Employee
Report Inappropriate Content
Message 12 of 17

Re: Rogue Sensor calling external IPs

Let me check with a peer advanced member to see if they have seen any of that behavior with rsd.  I will get back with you.

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

McAfee Employee cdinet
McAfee Employee
Report Inappropriate Content
Message 13 of 17

Re: Rogue Sensor calling external IPs

one quick question - in your original post you said that the sensor was updated.  Updated how specifically?

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

Re: Rogue Sensor calling external IPs

I don't know how, I'm pretty sure it's config'd to update automatically.  I monitor the rogues from a security and investigations standpoint, but don't administer the system itself.  I can only see in the ePolicy Orchestrator when the RSD "install" action type occurred. 

McAfee Employee cdinet
McAfee Employee
Report Inappropriate Content
Message 15 of 17

Re: Rogue Sensor calling external IPs

Ok, got it.

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

Re: Rogue Sensor calling external IPs

Good morning, are there any updates on information you may have been able to find regarding this?  Thanks!

McAfee Employee cdinet
McAfee Employee
Report Inappropriate Content
Message 17 of 17

Re: Rogue Sensor calling external IPs

We have not seen an internal sensor do any type port scans on any external systems.  If there is any way possible to capture a packet capture of that traffic, we can track it down, but without it, there isn't much we can prove or disprove either way. 

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

More McAfee Tools to Help You

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community