When I'm looking at the Malicious Broadcasts tab, I see the AP that saw the broadcasts, then there is a field for MAC. Is that the MAC of the AP or the MAC of the device that the malicious broadcasts originated from? I'm asking because I would assume the latter, but the MACs that are showing up are the MACs for the APs that says they saw the broadcasts. In other words, the row says "Seen By" AP1 (whose MAC is AA:BB:CC:DD:EE:FF:11) and "MAC" AA:BB:CC:DD:EE:FF:11. These are broadcast deauth packets.
... View more