To configure Suspicious Connection Service to block/log the C&C IP address:
- On the Apex One web console, go to Agents > Agent Management.
- Navigate to Settings and click Additional Service Settings.
- Under Suspicious Connection Service, tick Windows desktops or Windows Server platforms.
Click the image to enlarge.
- Go to Settings and click Suspicious Connection Settings.
- Tick Detect network connections made to addresses in the Global C&C IP list. For Apex One or newer, then select Log only or Block from the dropdown options.
Click the image to enlarge.
- Click Save.
- Test the connection to the C&C IP address. In Block mode, the alert will pop up and the log can be found under Suspicious Connection.