Hello
some of our customers asked me about this so I think this will help others, too.
2021-10-18 10:24:07
|
192.168.36.181
|
enabaonag_laptop
|
192.168.36.1
|
C2/Generic-A
|
www.google.com.512542883555094.windows-display-service.com
|
DNS
|
Drop
|
18010
|
2021-10-18 10:27:16Advanced threat protectionmessageid="18010" log_type="ATP" log_component="DNS" log_subtype="Drop" user="enabaonag_laptop" protocol="UDP" src_port="49584" dst_port="53" src_ip="192.168.36.181" dst_ip="192.168.36.1" url="www.google.com.512542883555094.windows-display-service.com" threat="C2/Generic-A" event_id="19AB3C00-B993-495E-9638-D7FD6F46BE7B" type="Standard" host_login_user="" host_process_user="" endpoint_id="" execution_path=""
Any remedy for this?
This thread was automatically locked due to age.