Chapter_11_CVE's and IoC's Flashcards
What part of Silent Defense runs the CVE and IoC checks?
The Industrial Threat Library (ITL) contains the CVE and IoC checks
When updating the CVE and IOC databases, what should be checked?
The synchronization status of each database for all Sensors
What blacklists are checked by the Network Indicators of Compromise (IoCs)?
DNS domains, IP address, file operations, &SSL client applications
How are file Indicators of Compromise (IoC’s) checked?
YARA rules and malicious file hashes
How often are CVE and IOC updates published byForescout?
Monthly
How do you update them in a SilentDefense deployment?
From Settings > Services > CVE and IOCs > Import submenu button
Once updated, what should be done?
Sync and scan historical network logs