cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
850
Views
0
Helpful
3
Replies

Anyone have a play book on investigation via FPMC?

babiojd01
Level 1
Level 1

I was interested in if anyone had a playbook they could share as it pertains to FirePower Managment center? If no playbooks can anyone share what their steps are as to:

1. What you personally investigate first? Impact 1?, IOC, Malware alerts...

2. What Cisco Recommends whats investigated first?

3. Cisco documentation on recommended steps for analysis?

 

 

3 Replies 3

rick11
Level 1
Level 1

Hello,

I didn't found any useful documentation, I can advice to look in other books but in general I would say

Impact 1 and Impact 2 events not blocked

What would stop an impact 1 or 2 event from being blocked? A Signature set to alert only?

Each signature can be set in Drop/Generate events/Disable state , depends how you configure it

Review Cisco Networking products for a $25 gift card