I have a throuble, Bitdefender Gravityzone EDR is detecting many correlated incidents, with a high score of impact in my organization. We are seeing that Bitdefender is receiving a wave of attacks from two domains. We are seeing that queries are made to several domains from 98 computers on the network, the actions have a high criticality score and according to what we see, different attack techniques are shown, how can I configure the Bitdefender Gravityzone Firewall to reject the connections and block unauthorized ports? // Is there a manual for the Firewall that comes with the gravityzone solutions?
I try to configure de firewall as show to follow:
¿There configuration is correct?
I leave some images for reference and see if any of you can guide me on what to do.
Impact or severity of event
Thank you.