While viewing threat incidents on the JATP Admin GUI, customers may notice multiple threats that are labeled "Rep_BL.CY."
This article defines what a threat that is labeled "Rep_BL.CY" means.
The display of threats labeled "Rep_BL.CY" on the JATP GUI indicates that JATP threat analysis detected a Command and Control (C&C) incident.
The "Rep_BL.CY" label indicates that there was communication with a known Reputation Blocklist IP (from our threat intel), that is, host 192.XXX.XXX.XX attempted to communicate with known threat hosts; that the threat was detected by the Reputation Blocklist cyphort; and it should be investigated.
By viewing the Infections tab on the JATP GUI, the configured Threat Feed that triggered the hit can be determined. The threat source would be the destination that the infected host attempted to contact. The threat target would be the "host" that is potentially infected and initiated the outgoing C&C attempt.
2020-12-31: Replaced words that failed to represent the inclusion and diversity Juniper values