Category – Knowledge Base

Articles

[Cyber Command] [Asset] [] Error in importing Asset [Illegal format of the request type field]
[Cyber Command] A large number of hosts were found to have scanning behavior on Endpoint security perception platform, but no Malicious File were found on the terminals
[Cyber Command] Access device alarm: Cascaded unsynchronized device Very-Low Risk
[Cyber Command] Accessing mss, error message when data reporting is enabled
[Cyber Command] After clicking OK on the large screen visual setting, the prompt: Submission error, guarantee start time => This input item is required
[Cyber Command] After Endpoint is processed, the previous processing status is still Pending
[Cyber Command] After Server joins the business group, the business group is still not displayed on the large screen
[Cyber Command] After VM deploys Cyber Command, restart and enter the installation interface again
[Cyber Command] Asset incident are not generated due to incorrect asset type
[Cyber Command] Automatic linkage NGAF does not take effect
[Cyber Command] Branch range configuration error causes attack screen to have no data
[Cyber Command] Check that there are more hosts to Endpoint week than in the last 30 days
[Cyber Command] Click "Mark as Processed" for Weak Password and submit slowly. The cascaded access to the upper-level platform is Offline
[Cyber Command] Cluster environment and NGAF configuration two-way authentication failed
[Cyber Command] Configuration data backup test FTP Server 21
[Cyber Command] Connectivity test failed when linked to Huawei firewall
[Cyber Command] Cross-layer 3 MAC is not effective
[Cyber Command] Cyber Command linkage NGAF and above, test prompts operation failure
[Cyber Command] Cyber Command system detection prompts "inserter platform core process abnormality" due to Critical expiration
[Cyber Command] Daily export has no data
[Cyber Command] Device management today's transmission log number does not match
[Cyber Command] Domain names that need to be released for Cyber Command3.0.64 to connect to Domain Name
[Cyber Command] Enabling high detection mode leads to a large number of misjudgments in web Secure logs
[Cyber Command] Export NGAF was detected to be infected with Cryptomining virus scanning behavior
[Cyber Command] Failed to delete the Offline docking device prompt, it has been referenced
[Cyber Command] Fair High Risk Host in the Host to be Pending is inconsistent with the number of High Risk Host in all risks
[Cyber Command] Inconsistent platform names result in "Permission denied" prompt when pulling API data
[Cyber Command] Inspection failed: Execute shell command: bash
[Cyber Command] Lateral access analysis is empty
[Cyber Command] Linkage IAG test authentication failure caused by cache
[Cyber Command] Linkage processing failure resulted in no subsequent automatic linkage
[Cyber Command] Many Branch Fair configured in Asset management, but only a few are displayed on the Branch screen
[Cyber Command] Mirrored vxlan data cannot be recognized
[Cyber Command] Modify the network port Very-Low Risk and the prompt "NIC status modification failed, please check the interface status"
[Cyber Command] NGAF temporarily blocked IPs reaching the upper limit, resulting in linkage error
[Cyber Command] Secure incident linkage NGAF prompt requires NGAF version
[Cyber Command] Situation Awareness detected that Endpoint had port 161 open, but the port was not actually open
[Cyber Command] STA [System] – [Secure Perception Platform] Configuration submission error
[Cyber Command] STA and Cyber Command version incompatibility causes STA to synchronize logs to Cyber Command abnormally
[Cyber Command] STA cannot connect using the upgrade client, prompting that the device cannot be connected. Please check whether the network is normal.
[Cyber Command] STA delay caused by the probe system time lag
[Cyber Command] STA has traffic and threat data, but Cyber Command has no Secure log
[Cyber Command] STA upgrade client prompt: Failed to obtain public network time, upgrade serial number verification failed
[Cyber Command] STA upgrade prompt: Software upgrade serial number verification failed (errno:41)
[Cyber Command] Synchronize Secure log to Cyber Command, website access log is not displayed on Cyber Command
[Cyber Command] The console prompts that the File Threat signature library is missing
[Cyber Command] The content of the email alarm log is empty
[Cyber Command] The contents of weak password log files downloaded from the same time period are different after a period of time
[Cyber Command] The large screen is visible without Branch and the large screen has not switched to the multiBranch self-operation and maintenance scenario
[Cyber Command] The navigation labels on the homepage of the same perception platform are displayed Tag opened in different browsers
[Cyber Command] The operating device console occasionally crashes and prompts "out of memory"
[Cyber Command] The risk business perspective has marked a Server as processed, but the number of processed events in the overview interface is still 0
[Cyber Command] The security center does not display the log content of NGAF synchronization
[Cyber Command] The STA browser page does not display a "STA"
[Cyber Command] The top 5 data of major network activities to ensure large screen Attack Source is empty
[Cyber Command] The upper limit of the data reported by the financial situation awareness platform is set, resulting in data failure to report
[Cyber Command] Token error message when NTA301y is linked to NGAF
[Cyber Command] Unable to detect virus files due to mistakenly opening sandbox configuration
[Cyber Command] Upgrade management does not see STA online, and the STA rule base cannot be upgraded
[Cyber Command] Upgrade to 3.0.58 prompts appre error
[Cyber Command] Using Firefox to open the processing center error report
[Cyber Command] Virtual vCyber Command gateway id duplication issue
[Cyber Command] When adding Endpoint Secure in Cyber Command Correlated Response, it prompts that adding instance fails and clicks test and fails
[Cyber Command] When opening the device management interface of Cyber Command, an error message is displayed: "Error information about the device ID collection field cannot be obtained! (check_devids_array_format)"
[Cyber Command] When viewing Risky User, it prompts that you do not have permission
[NTA] There is a risk alert but there is no corresponding hot incident
[STA] STA cannot collect mirrored traffic
[STA] STA does not support importing configuration files of different devices. It only supports importing configuration files of the same version and the same device.
【Cyber Command】Abnormal display of name on large screen
【Cyber Command】All attacks were directed to Guangdong in the network attack situation screen, but not to the province where Cyber Command is located.
【Cyber Command】Asset were not returned normally
【Cyber Command】Associate multiple Asset with the same mac
【Cyber Command】Connection to Cloud Mirror authentication failed
【Cyber Command】Cyber Command Asset are duplicated, but Asset groups are different
【Cyber Command】Data center visual prompt Server is not configured
【Cyber Command】External attack overview has no data
【Cyber Command】Global whitelist with no Secure incident
【Cyber Command】IAG accesses Cyber Command, user authentication Very-Low Risk fails
【Cyber Command】Large screen visible without external visual display module
【Cyber Command】Log search does not contain any logs related to the Internet
【Cyber Command】Security Center-Security Threat Intelligence Customized Threat Intelligence Sources
【Cyber Command】STA system status shows that the number of threats is 0
【Cyber Command】The processed data will still be displayed on the big screen
【STA】After STA updates the authorization, the status shows as not activated
3.0.77 Ransomware type Secure alerts are not found in the Analysis Center – Ransomware page
3.0.81-3.0.83 Vulnerability report export exception, data is template data [latest]
Analysis Center Evasive Attack Filter Conditions
Common third-party access issues
Cyber Command Asset scanning configuration scanner cannot display STA version is too low
Cyber Command is linked to Endpoint Secure, but Cyber Command always shows that Endpoint Secure is not installed
Cyber Command linkage NGAF cannot issue Correlated Block
Cyber Command shows that the AF on the cloud security service platform is Offline and cannot be disconnected
Cyber Command system settings – general configuration – proxy Server effective range description
Cyber Command3.0.77 System command injection incident cannot view details
Cyber Command3.0.83 imports the 3.0.67 STA upgrade package and prompts that it already exists
STA send traffic to port 4300 of CC
The risk host has been handled for a month, and the score Fair homepage overview is less than 100 points
Whitelist is not effective. The Whitelist validity period has expired.
Why traffic does not generate Secure alerts or Secure incident troubleshooting guide
【CC】STA send traffic to port 4300 of CC
【CC】CC unable to submit the custom security event and show illegear character.
【CC】Rollback patch in CC# Issue Description # Error/Warning Information # Handling Process # Root Cause # Solution
【CC】Unable to submit custom security event
【CC】Rollback patch when perform upgrade
【CC】Unable to display/detect interface other than Management port on vSTA.
GoldenEye Details Error: Database is busy
[Integration] CC integrate ES SAAS
+ 407 Articles
Show Remaining Articles