cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
841
Views
0
Helpful
3
Replies

Anyone have a play book on investigation via FPMC?

babiojd01
Level 1
Level 1

I was interested in if anyone had a playbook they could share as it pertains to FirePower Managment center? If no playbooks can anyone share what their steps are as to:

1. What you personally investigate first? Impact 1?, IOC, Malware alerts...

2. What Cisco Recommends whats investigated first?

3. Cisco documentation on recommended steps for analysis?

 

 

3 Replies 3

rick11
Level 1
Level 1

Hello,

I didn't found any useful documentation, I can advice to look in other books but in general I would say

Impact 1 and Impact 2 events not blocked

What would stop an impact 1 or 2 event from being blocked? A Signature set to alert only?

Each signature can be set in Drop/Generate events/Disable state , depends how you configure it

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card