Skip to main content

2 replies

AnthonyH
Staff
Staff
October 15, 2024

Hello Tamiltk,

 

Could you further explain what is occurring? Are there any logs under Log & report -> Security Events -> IPS, about traffic being bypass/blocked?

Tamiltk
TamiltkAuthor
Explorer
October 17, 2024

There wasn't any incident triggered on this subject. I just need an artifact that Fortigate IPS does support Covert Malware communication detection

kaman
Staff
Staff
October 17, 2024

Hi Tamiltk,

From the IPS signatures' point of view, we have signatures to detect botnet communication, remote access tools, reverse shells, etc. To detect communications over covert channels, make sure an IPS sensor with all signatures is enabled with the default action, as it should detect and/or block these communications.

Please enable deep inspection, as most of the traffic is in the HTTPS protocol and needs to be decrypted.

If you have found a solution, please like and accept it to make it easily accessible to others.