While working on threat detection content development you observe some odd activity in the firewall logs. You notice a number of allowed HTTP connections outbound from a client's environment (Client IP - 192.168.10.15) towards a Russian IP address - 185.211.245.198. After further investigation you notice these HTTP connections seem to happen on a regular basis, even during off hours, in what looks to be a pattern. You know that this client's IP belongs to one of their user subnets and that this client has no business with or in Russia. We have no IDS or Anti-virus alerts for this device at this time. Please write up an escalation case communicating the observations, level of concern, and recommended actions to the client.
While working on threat detection content development you observe some odd activity in the firewall logs. You notice a number of allowed HTTP connections outbound from a client's environment (Client IP - 192.168.10.15) towards a Russian IP address - 185.211.245.198. After further investigation you notice these HTTP connections seem to happen on a regular basis, even during off hours, in what looks to be a pattern. You know that this client's IP belongs to one of their user subnets and that this client has no business with or in Russia. We have no IDS or Anti-virus alerts for this device at this time.
Please write up an escalation case communicating the observations, level of concern, and recommended actions to the client.
Step by step
Solved in 2 steps