Indications of compromise events
An Indication of Compromise (IoC) event is a security detection mechanism that
-
identifies connection events with a very high malware confidence level, as reported by EVE,
-
triggers for encrypted sessions generated from a host using a malicious client, and
-
provides information such as the IP address, MAC address, operating system information of the malicious host, and timestamp of the suspicious activity.
IoC event generation and viewing locations
A session with an Encrypted Visibility Threat Confidence score of 'Very High' as seen in connection events generates an IoC event. You must enable Hosts from . In the Cloud-Delivered Firewall Management Center, you can view the IoC event existence from these locations:
-
, and then .
-
> Choose the host that must be checked.
You can view the process information of the session that generated the IoC on the Connection Events page. Click to access the Connection Events page. Note that you must manually select the Encrypted Visibility fields and IoC field from the Table View of Connection Events tab.