Viewing C&C Callback Logs
- Go to or .
- In the agent tree, click the root domain icon () to include all agents or select specific domains or agents.
- Click or .
- Specify the log criteria and then click Display Logs.
View logs. Logs contain the following information:
The time the detection occurred
The user logged on at the time of the detection
The endpoint from which the callback originated
The IP address of the compromised host
The domain of the endpoint on which the detection occurred
The address to which the endpoint sent the callback
C&C List Source
The C&C list source that identified the C&C server
C&C Risk Level
The risk level of the C&C server
The Internet Protocol used for the transmission
The process that initiated the transmission (path\application_name)
The action taken on the callback
If Web Reputation blocked a URL that you do not want blocked, click the
Add to Web Reputation Approved List button to add the
address to the Web Reputation Approved List.
OfficeScan can only add URLs to the Web Reputation Approved List. For detections made by the Global C&C IP List or the Virtual Analyzer (IP) C&C List, manually add these IP addresses to the User-defined Approved C&C IP List.
For details, see Configuring Global User-defined IP List Settings.
- To save logs to a comma-separated value (CSV) file, click Export All to CSV. Open the file or save it to a specific location.