SigmaHQ/rules/network/net_susp_network_scan.yml
2019-11-12 23:12:27 +01:00

23 lines
556 B
YAML

title: Network Scans
id: fab0ddf0-b8a9-4d70-91ce-a20547209afb
description: Detects many failed connection attempts to different ports or hosts
author: Thomas Patzke
logsource:
category: firewall
detection:
selection:
action: denied
timeframe: 24h
condition:
- selection | count(dst_port) by src_ip > 10
- selection | count(dst_ip) by src_ip > 10
fields:
- src_ip
- dst_ip
- dst_port
falsepositives:
- Inventarization systems
- Vulnerability scans
- Penetration testing activity
level: medium