Configure the following event notification to notify administrators when communications between multiple endpoints and known C&C callback addresses have been detected.
The Event Notifications screen appears.
A list of events appears.
The C&C Callback Outbreak Alert screen appears.
Settings |
Description |
---|---|
C&C list source |
Select one or more C&C list sources. |
Callback attempts |
Specify the number of callback attempts. |
Compromised hosts |
Specify the number of compromised hosts. |
Period |
Specify the period of time. |
The selected contact groups or user accounts appear in the Selected Users and Groups list.
Method |
Description |
---|---|
Email message |
To customize the email notification template, use supported token variables or modify the text in the Subject and Message fields. For more information, see Standard Token Variables and C&C Callback Token Variables. |