Last edited by Draiden 11 May 2023 15:16.

Last edited by Draiden 10 May 2023 18:49.

Last edited by Draiden 04 May 2023 21:16.



So its been awhile. I tooked my vacay and came back saw this alert from my 2nd layer SIEM.
does EDR intentionaly going to turn off firewall?

And maybe this is why my EDR agent Icon got red dots?




EDIT:

I found out that during CC+ES correlation when triggered ES will do deep scan. So since its hosted on a server, agent needs ask for turning it off while doing some errunds.

Thanks guys!

EDIT:

Case solved. Just clumsy after a long vacation..

CLELUQMAN has solved this question and earned 40 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins, 20 coins of bounty and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

have u solve this? i think the EDR turn off the firewall is temporary , maybe it is updating or scanning.
Is this answer helpful?
Draiden Lv2Posted 05 May 2023 14:44
  
I have solved the image below.. (notifications only) But the upper image is kinda worries me.
Can anyone send me a working legit hash for edr_monitor and edr_agent?

I Can Help:

Change

Moderator on This Board

18
8
0

Started Topics

Followers

Follow

Trending Topics

Board Leaders