Guest User!
You are not Sophos Staff.
Hi,
ATP is giving me a detection of C2/Generic-A from a User/Host that is a public IP that has nothing to do with our network.
Any advise on where I should start investigating?
Thanks
What information can you get on that public IP when you do a who-is lookup on it? Also, what port was it reporting as using?