1 2 Previous Next 11 Replies Latest reply on Feb 12, 2015 2:24 AM by jo_impakt

    Suspicious host ::1 ??

    jo_impakt

      Hi,

       

      I have correlation rules firing up about suspicious host for ::1. Apparently this would be in the watchlist: "Botnet - Bot". This doesn't make any sense and generates a lot of false positives, also with other rules.

       

      Why is this there? Please find a screenshot attached

       

      Kind regards

      Jo

        1 2 Previous Next