Skip to content

Latest commit

 

History

History
42 lines (35 loc) · 1.51 KB

THRESHOLD-S00514.md

File metadata and controls

42 lines (35 loc) · 1.51 KB

Rules: Intrusion Scan - Targeted

Description

This rule looks for an intrusion product detecting an internal IP sending different exploits to another IP in a short timeframe.

Additional Details

Detail Value
Type Threshold
Category Discovery
Apply Risk to Entities user_username, srcDevice_ip, srcDevice_hostname
Signal Name Intrusion Scan - Targeted
Summary Expression Targeted intrusion scan from IP: {{srcDevice_ip}}
Threshold Count 5
Threshold Window 5m
Score/Severity Static: 4
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0007, _mitreAttackTechnique:T1046

Vendors and Products

Fields Used

Origin Field
Normalized Schema listMatches
Normalized Schema normalizedSeverity
Normalized Schema srcDevice_hostname
Normalized Schema srcDevice_ip
Normalized Schema srcDevice_ip_isInternal
Normalized Schema threat_ruleType
Normalized Schema user_username