Just Published! Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

EDR: Are TCP Netconn Events Only for Established Connections?

EDR: Are TCP Netconn Events Only for Established Connections?

Environment

  • EDR: All Supported Versions

Question

Is TCP netconn events only for established connections?

Answer

  • The EDR product doesn't have a way to differentiate between an established connection versus an attempt.
  • They will both be color coded purple in the WebUI.
  • Customers would have to review firewall or perimeter device logs to see exactly what that traffic was doing. 

Additional Notes

There is also no way to search IP by outbound or inbound communication

Related Content


Labels (1)
Tags (2)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎12-07-2018
Views:
401
Contributors