Logs > Agents > Security Risks
Agents > Agent Management
From the Security Risk Logs screen, click View Logs > C&C Callback Logs.
From the Agent Management screen, click Logs > C&C Callback Logs.
Item |
Description |
---|---|
Date/Time |
The time the detection occurred |
User |
The user logged on at the time of the detection |
Compromised Host |
The endpoint from which the callback originated |
IP Address |
The IP address of the compromised host |
Domain |
The domain of the endpoint on which the detection occurred |
Callback Address |
The address to which the endpoint sent the callback |
C&C List Source |
The C&C list source that identified the C&C server |
C&C Risk Level |
The risk level of the C&C server |
Protocol |
The Internet Protocol used for the transmission |
Process |
The process that initiated the transmission (path\application_name) |
Action |
The action taken on the detection |
Apex One can only add URLs to the Web Reputation Approved List. For detections made by the Global C&C IP List or the Virtual Analyzer (IP) C&C List, manually add these IP addresses to the User-defined Approved C&C IP List.
For details, see Configuring Global User-defined IP List Settings.