I have the following log and I am confused by the "direction=" portion.
The following log shows "direction=outgoing", which would mean in return
flow traffic, the the original dstIP is now sending out an infected
file, is that right, or is the "direc...