Professional Documents
Culture Documents
Organization: Super/Global
User Notes
Incident: 933148
Event Severity HIGH Incident Last May 28 2023, 03:32:30 AM Event Name Permitted Traffic from FortiGuard Malware IP List
Category Occurrence Time
Incident PORTAL-FRONT.dgpad.org Incident Source srcIpAddr:172.104.227.98, Incident Target destIpAddr:172.16.10.213,
Reporting Device
Incident Detail Incident Status Active Incident Open
Resolution
Incident ID 933148 Event Type PH_RULE_FROM_FORTIGUARD_MALWARE_IP Incident Ticket New
Status
Business Service Count 6 Incident Cleared
Name Time
Incident Ticket Incident Impacts
User Notification
Recipients
Incident Cleared Incident Event Severity 9
Reason Comments
Incident First May 27 2023, 01:05:30 AM Incident 172.16.10.213 Incident Ticket ID 339194071
Occurrence Time Reporting IP
Organization UNGRD Incident Incident Cleared
Name Notification User
Status
Incident Incident Incident
Externally Externally Cleared Externally
Assigned User Time Resolution Time
Incident External Incident External Incident External
Ticket ID Ticket State Ticket Type
Incident View Read Raw Event Log Incident Category Security
Status
Incident Exfiltration Incident Approved Incident Title Traffic from FortiGuard Malware IP 172.104.227.98 to
Subcategory Reporting Device 172.16.10.213
Status
Incident Tag Attack Technique Exfiltration Over C2 Channel(T1041) Attack Tactic Exfiltration
Name
IP Address Host Name Organization ID Country State City Region Building Floor