Create Metadata Streaming Profile to Detect Command-and-Control (C2) Communications
-
In the Metadata Streaming Profiles section, click +.
The Create Metadata Streaming Profile page is displayed.
- Enter a unique profile name within 63 alphanumeric characters. You can use special characters such as _ and -.
- In the HTTP section, enable the Encrypted c2 toggle button.
-
Select how you want to log a request:
-
Log detections—Log the request only if a threat is detected.
-
Log everything—Log all requests received by the device.
-
- Enable the Fallback options log toggle button to log the request if no threat is detected.
-
Click OK.
The metadata streaming profile is created and displayed on the Metadata Streaming Policy page.