Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Sophos XG Applications defining pCloud

Hello, I turned on traffic filtering on our firewall and am trying to identify the traffic that Sophos is Labeling pCloud.  There is a pCloud.com Backup and storage

When I attempt to login connect to one of the hosts https://52.20.148.96/ it throws a warning and when I look at the certificate, the certificate is Agent.Jumpcloud.com.  Since it is on all our machines and the Certificate is for agent.jumpcloud.com it seems legitimate.  Lots of systems have a steady amount of traffic with this App name.  The IP addresses are all in AWS and all have the agent.jumpcloud.com SSL certificate.  So I am confident that this is our Jumpcloud agents calling home.

At first, I thought it might be a widespread infection sending data to cloud storage.

Is there a process on the Sophos to refine the Application Details?  Is there a way to know what causes the traffic to be labelled pCloud.

Best,


Tom

Application Detail Name pCloud
Category Storage and Backup
Risk Medium
Characteristics Transfer files,Prone to misuse,Widely Used
Technology Browser Based
Dependency None
Applicable on 16.01.0 Build 101 and above
Description This indicates pCloud website or application access attempt from the network.



This thread was automatically locked due to age.
Parents Reply Children
No Data