Knowledge Base

EventSentry can detect malicious activity in a variety of ways including: Failed Logons RDP ... Log File Activity Outgoing process activity Port Scans NetFlow Windows Syslog Once a malicious IP is detected it can be helpful to report the IP address to an online reputation system for IP addresses like abuseipdb.com. Automatic...

KB-ID 547
Category: Integration

Starting with version 4.2.3 EventSentry supports custom threat feedshttps://www.eventsentry.com/documentation/help/html/configglobaloptions.htm black lists in addition to the builtin threat feeds. EventSentry loads additional IP address from the following file: systemroot\system32\eventsentry\temp\eventsentrythreatintelcustom.tmp ...

KB-ID 442
Category: Security
Applies to: 4.2.3