Guest User!
You are not Sophos Staff.
My SEIM (AlienVault) is detecting Mirai inbound activity.
Eg:
How can these be stopped at the UTM?
Eg can it get known botnet addresses from the Open Threat Exchange (OTX)?
Thanks, James.
Have you considered using Country Blocking?
XG 19.5 GA 64-bit | Intel Xeon 4-core v3 1225 3.20Ghz 16GB Memory | 500GB SSD HDD | GB Ethernet x5
Thanks Amodin - we do use country blocking for some countries, but it's a botnet so that won't work.