Skip to content

Latest commit

 

History

History
48 lines (41 loc) · 2.22 KB

THRESHOLD-S00074.md

File metadata and controls

48 lines (41 loc) · 2.22 KB

Rules: Excessive Firewall Denies

Description

This rule is designed to detect excessive firewall blocks within a shortened time frame. Customers will need to adjust the threshold of this rule to align with their environment's normal vs abnormal firewall traffic patterns.

Additional Details

Detail Value
Type Threshold
Category Discovery
Apply Risk to Entities srcDevice_ip
Signal Name Excessive Firewall Denies
Summary Expression Excessive firewall denies for source IP: {{srcDevice_ip}}
Threshold Count 100
Threshold Window 5m
Score/Severity Static: 1
Enabled by Default False
Prototype False
Tags _mitreAttackTactic:TA0007, _mitreAttackTechnique:T1046

Vendors and Products

Fields Used

Origin Field
Normalized Schema action
Normalized Schema objectType
Normalized Schema srcDevice_ip