Falco informational stable other
Unexpected UDP Traffic
Detecting UDP traffic on ports other than 53 (DNS) or other commonly used ports. Misusing UDP is a known TTP among attackers. Monitoring unusual network activity is highly valuable but often generates significant noise, as is the case with this detection.
Detection Logic
inbound_outbound and fd.l4proto=udp and not expected_udp_traffic Field Validations
Loading…
Comments (0)
Loading comments...