Configure the following event notification to notify administrators when communications
between multiple endpoints and known C&C callback addresses have been detected.
Procedure
- Go to .The Event Notifications screen appears.
- Click Advanced Threat
Activity.A list of events appears.
- In the Event column, click C&C callback outbreak
alert.The C&C Callback Outbreak Alert screen appears.
- Specify the following notification settings.SettingsDescriptionC&C list sourceSelect one or more C&C list sources.Callback attemptsSpecify the number of callback attempts.Compromised hostsSpecify the number of compromised hosts.PeriodSpecify the period of time.
- Select recipients for the notification.
- From the Available Users and Groups list, select contact groups or user accounts.
- Click >.The selected contact groups or user accounts appear in the Selected Users and Groups list.
- Enable one or more of the following notification methods.MethodDescriptionEmail messageTo customize the email notification template, use supported token variables or modify the text in the Subject and Message fields.For more information, see Standard Token Variables and C&C Callback Token Variables.
- To test if recipients can receive the event notification, click Test.
- Click Save.