Procedure
- Go to .The Outbreak Notifications screen appears.
- On the Criteria tab in the C&C Callbacks section, configure the
following:
Option Description Same compromised hostSelect to define an outbreak based on the callback detections per endpointC&C risk levelSpecify whether to trigger an outbreak on all C&C callbacks or only high risk sourcesActionSpecify which actions Apex One counts to determine an outbreak scenarioDetectionsSpecify the number of detections that Apex One must exceed to trigger an outbreak scenarioTime periodSpecify the monitoring period - On the Email tab:
- In the C&C Callbacks section, select Enable notification via email.
- Specify the email recipients beside the To field.
- Specify the Subject used in the email notification.
- Specify the Message contents.Apex One supports use of tokens in the Subject and Message fields.
Token Variables for C&C Callback Outbreak Notifications
Variable TokenDescription%CNumber of C&C callback logs%TTime period when the C&C callback logs accumulated - Specify any additional log data you want to include
in the notification (in tabular format).Log ColumnDescriptionDate/TimeDate and time of detectionCompromised HostEndpoint with the detectionIP AddressIP address of the compromised hostDomainThe domain of the endpoint on which the detection occurredCallback AddressThe URL that triggered the detectionC&C Risk LevelThe risk level of the callback addressC&C List SourceThe C&C list source that identified the C&C serverActionAction performed on the security risk
- In the SNMP Trap tab:
- Go to the C&C Callbacks section.
- Select Enable notification via SNMP trap.
- Accept or modify the default message. You can use token variables to represent data in the Message field. See Token Variables for C&C Callback Outbreak Notifications for details.
- In the NT Event Log tab:
- Go to the C&C Callbacks section.
- Select Enable notification via NT Event Log.
- Accept or modify the default message. You can use token variables to represent data in the Message field. See Token Variables for C&C Callback Outbreak Notifications for details.
- Click Save.