I have an issue where some older (EOL) AXIS Cameras trigger a TRUFFLEHUNTER TALOS 2020-1018 alert, for which there is no additional information available other than our MX detects some command and control activity. Due to the nature of this device and the server that it is connecting to, I believe that this is expected. Video Security server connecting to a camera. However, identical cameras with identical firmware releases do not exhibit the same MX alert.
I am hesitant to whitelist this because of incomplete information and resetting the camera to factory default with firmware flashing does not resolve the issue. Only camera replacement with another unit solves the alert issue.
Where this could eventually be an issue is when dozens of cameras that have gone EOL start exhibiting the same behavior. As a school district, we push hardware life as far as possible, but the concerns of compromised IoT hardware have accelerated our replacement schedule. It is not like I have Huawei cameras hanging everywhere but replacing a camera exhibiting the issue with identical (model, vintage and firmware) resolves the issue.
Anyone with similar experiences?