Trellix Endpoint Security blocked web control violation detected
このページは日本語には対応しておりません。随時翻訳に取り組んでいます。
翻訳に関してご質問やご意見ございましたら、
お気軽にご連絡ください。
Goal
Detect threats related to web control violations which are blocked by Trellix Endpoint Security.
Strategy
Monitor endpoint security events for indications of blocked web control violations. Focus on analyzing the context of the event, including the specific website or URL that was blocked, and the affected endpoints.
Triage and Response
- Confirm the details of the blocked web control violation, such as the restricted URL or category.
- Review the event details to understand the nature of the violation.
- Examine the impacted endpoint using its hostname -
{{@attributes.analyzerhostname}}
and IP address - {{@attributes.analyzeripv4}}
. - Ensure the web control policies are properly enforced to prevent access to restricted content in the future.
- Continue to monitor the affected endpoints for further violations or related anomalies.