Views:

To enable Suspicious Connection Service:

  1. Log in to the Apex Central Management console, and go to Policies > Policy Management.

    Suspicious Connection Settings

  2. Click Create.

    Suspicious Connection Settings

  3. Create Policy name.
  4. Select “Specify Target(s)” and click Select.

    Suspicious Connection Settings

  5. Assign a target to policy.

    Specifying Target can be done multiple ways:

    • Match Keywords (Hostname/Apex Central display name/Apex Once domain heirarchy)

      Suspicious Connection Settings

    • IP Address
    • Operating System
    • Browse the Product Directory

      Suspicious Connection Settings

  6. Once a target is selected, click Add selected Targets > Ok.

    Suspicious Connection Settings

    The page will be redirected back to Policy management.

  7. Scroll down and look for Suspicious Connection Settings, then click the drop-down.
  8. Enable the following:
    • Detect network connections made to addresses in the Global C&C IP list
    • Detect connections using malware network fingerprinting:
      • Indicate the action as either BLOCK or LOG

        Suspicious Connection Settings

  9. Click Deploy.

    Suspicious Connection Settings

  1. Go to the Apex One Management console > Agents tab > Agent Management.

    Suspicious Connection Settings

  2. Select the Group to configure.
  3. Click Settings > Suspicious Connection Settings.

    Suspicious Connection Settings

  4. Enable the following:
    • Detect network connections made to addresses in the Global C&C IP list
    • Detect connections using malware network fingerprinting:
      • Indicate the action as either BLOCK or LOG

        Suspicious Connection Settings

  5. Click Apply To all Agents/Apply to Future Domains Only.