Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ATP Alert - Confused

Hi,

ATP is giving me a detection of C2/Generic-A from a User/Host that is a public IP that has nothing to do with our network.

Any advise on where I should start investigating?

Thanks



This thread was automatically locked due to age.
Parents Reply Children
  • Hi Vilic,

    Thanks - that's exactly what the problem was. The IP address was the one mentioned by all the other posters in that discussion.

    Still not sure how the alert happened in that I thought ATP dealt with outgoing connections, but I'll switch across to the existing thread.

    Thanks again.