Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

how often can ATP provide False positves?

Hi all,

 

just a short question, is it possible that the ATP just hits a false positive? We have a report of generic Command and Control from the site: 

exactlywhatistime com
 
a basic site about relativity theory and time, but the UTM did alert due to Botnet. 
Any ideas if there may be false positives around, or seems valid?
 
Thanks in advance!
Gergö


This thread was automatically locked due to age.
Parents
  • Hi Gergö,

    the short answer is yes, could be, but very rare. Sometimes these were triggered by non optimal configuration of DNS and so on.

    If you like tell us some more details and a lot of people here are willing to help.

    So maybe show us the log entry for that ATP hit. 

    best regards 

    Alex

Reply
  • Hi Gergö,

    the short answer is yes, could be, but very rare. Sometimes these were triggered by non optimal configuration of DNS and so on.

    If you like tell us some more details and a lot of people here are willing to help.

    So maybe show us the log entry for that ATP hit. 

    best regards 

    Alex

Children
No Data