Question

P2P network connection detect rule

  • 19 October 2023
  • 1 reply
  • 24 views

Hello everyone,
Being searching LP blogs and community to see if we have any detection rules for P2P network connections. Came out there is a rule to finding P2P applications but nothing of useful to find the network connection. Any tips or suggestions in building a P2P detection will be much appreciated. 

Thanks


1 reply

Userlevel 4
Badge +7

Hi,

I don’t think that’s something that we can do on our own - we would need the relevant data for example from a next generation firewall. Logpoint doesn’t do packet inspection and doesn't hook into the network itself - so the question is which device would pick up this kind of traffic, report it back to Logpoint, and how?

Reply