RT6600ax ET INFO Suspicious Domain (*.icu) in TLS SNI triggered by SynoForum

Currently reading
RT6600ax ET INFO Suspicious Domain (*.icu) in TLS SNI triggered by SynoForum

72
16
NAS
DS918+ DS1522+
Router
  1. MR2200ac
  2. RT6600ax
Operating system
  1. macOS
Mobile operating system
  1. iOS
Hi guys
Whenever I open this forum, I get this Threat Prevention Alert: "ET INFO Suspicious Domain (*.icu) in TLS SNI"

SCR-20240121-mnwq.png


Even though I trust this site (and I'll probably set this alert to Do Nothing), this raises a question:
Does Synology publish a site/document where it explains in details each rule that trigger the Alert/Drop Events that we see in TP?

I've read their TP documentation, but it's very basic. And nothing to be found on the web either.
 
Hi,

We run Matomo analytics over the .icu domain so it should be fine.

Does Synology publish a site/document where it explains in details each rule that trigger the Alert/Drop Events that we see in TP?
Not that I know.
 
Upvote 0
Upvote 0

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Similar threads

:) I thought you knew. Thats why i mentioned ziggo. ;)
Replies
6
Views
2,954

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Trending threads

Back
Top