Guest User!
You are not Sophos Staff.
My SEIM (AlienVault) is detecting Mirai inbound activity.
Eg:
How can these be stopped at the UTM?
Eg can it get known botnet addresses from the Open Threat Exchange (OTX)?
Thanks, James.
Have you considered using Country Blocking?
Thanks Amodin - we do use country blocking for some countries, but it's a botnet so that won't work.