Some malware uses UDP traffic to exfiltrate data. The Endpoint Security (HX) xAgent allows you to monitor and capture UDP network event traffic on your host endpoint so you can review and respond to potential compromises.
You can enable UDP network event capturing through real-time indicator detection processing using the Web UI or the API. This section covers how to enable UDP network event capturing for real-time indicator detection indicator using the Web UI. See the Endpoint Security (HX) REST API Guide for more information on configuring your real-time indicator settings.
Important
On hosts with a high number of events, some events may not be recorded.
Admin access to the Web UI
Enabling UDP Network Event Capture
To enable UDP network event capture for all of your host endpoints:
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
From the Policies table, select the Agent Default Policy and click the policy link to access the Edit Policy page.
Select the Real-Time Indicator Detection tab.
.png)
Verify that the Real-Time Indicator Detection ON/OFF switch is set to ON to enable real-time indicator detection.
.png)
In the Events section, toggle the Capture UDP Events ON/OFF switch to ON
.png)
Click Save.
To enable UDP network event capture for selected host sets:
Note
See Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
From the Policies table, click the link for the custom policy you want to modify.
Select the Real-Time Indicator Detection tab.
.png)
Verify that the Real-Time Indicator Detection ON/OFF switch is set to ON to enable real-time indicator detection.
.png)
In the Events section, toggle the Capture UDP Events ON/OFF switch to ON
.png)
Click Save.
Now you can assign host sets to the custom policy and set the policy priority level. See Assigning Host Sets to Agent Policies and Configuring Policy Priority Using the Web UI for more information.
Disabling UDP Network Event Capture
To disable UDP network event capture for all of your host endpoints:
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
From the Policies table, select the Agent Default Policy and click the policy link to access the Edit Policy page.
Select the Real-Time Indicator Detection tab.
.png)
In the Events section, toggle the Capture UDP Events ON/OFF switch to OFF.
.png)
Click Save.
To disable UDP network event capture for selected host sets:
Note
If you disable a setting in a custom policy, the setting is disabled for all host sets assigned to the policy. If you want select host sets to keep the original setting, you must create a new custom policy with the setting enabled and assign it to the selected host sets. See Creating a Custom Policy for more information about using the Web UI to create a custom policy.
Log in to the Web UI as an administrator.
From the Admin menu, select Policies to access the Policies page.
From the Policies table, click the link for the custom policy you want to modify.
Select the Real-Time Indicator Detection tab.
.png)
In the Events section, toggle the Capture UDP Events ON/OFF switch to OFF.
.png)
Click Save.