Firewall deny burst to a printer vendor update service
A-105800:00time on this alert, target 30 minutes
Back to queueAlert details
- Source
- Firewall
- Detection rule
- FW-DENY-BURST-021
- Affected user
- t.alvarez
- Affected host
- WKS-QA-11
- Source IP
- 23.62.99.130
- First seen
- 2026-07-24T16:12:00Z
Why this fired, in plain English
The firewall blocked the same connection many times in a row.
Suggested playbook
Malware detection on an endpoint
- 1. Read the action field first: blocked/quarantined changes urgency dramatically versus alert_only.
- 2. Identify the process path. AppData, Temp and Users\Public are common malware locations.
- 3. Check the parent process — Office apps spawning shells is abnormal.
- 4. Look up the file hash for a verdict and first-seen date.
Raw log evidence
Exactly what the tools recorded — 3 events.
Guided hint: this line matters
ts=2026-07-24T16:10:02Z src="firewall" action=deny src_ip=10.20.31.44 dest_ip=23.62.99.130 dest_port=8443 proto=tcp rule="default-deny-egress" attempt_count=44 app="printer-update"
Port 8443 is not in the allowed egress list, so the default deny rule catches it.
Guided hint: this line matters
ts=2026-07-24T16:10:02Z host=WKS-QA-11 EventID=4688 process_name="C:\\Program Files\\Kyocera\\KMUpdater\\kmupdate.exe" parent_process="services.exe" signed=true signer="Kyocera Document Solutions"
A digitally signed program from the printer vendor, installed in Program Files.
Guided hint: this line matters
ts=2026-07-24T16:12:00Z src="threatintel" event=lookup ip=23.62.99.130 owner="Akamai CDN" classification=benign customer="Kyocera"
Related events
The order things happened in.
16:10Z
44 blocked update attempts
16:12Z
Deny-burst alert raised
Enrichment lookups
Mock lookups. Run each one yourself — a real analyst never guesses what a lookup would have said. There is no "run everything" button on purpose.
Not checked yet.
Not checked yet.
Not checked yet.
techniques
Your verdict
Keyboard shortcuts 1–4, or click. You can always change your mind afterwards.