The connections coming from OfficeScan agent going to the C&C IP address in our list can only be logged. These connections have no pop-up alerts and cannot be blocked too. You will notice this behavior every time the OSCE agent detects a network connection to the C&C IP address.
This is a product design and users cannot modify this behavior.
To check this behavior:
- From the OSCE web console, go to Agents > Agent Management > Settings.
- Select the "Suspicious Connection Settings".
- Check "Detect network connections made to addresses in the Global C&C IP list:" to enable the Suspicious Connection Service on the OSCE agenot.
- Test the connection to the C&C IP address.
- On the Agent console, go to Log.
- Under the C&C callback log and suspicious connection log, you can see that the C&C IP address connections are only logged.