Falco informational stable other

Unexpected UDP Traffic

Detecting UDP traffic on ports other than 53 (DNS) or other commonly used ports. Misusing UDP is a known TTP among attackers. Monitoring unusual network activity is highly valuable but often generates significant noise, as is the case with this detection.

View Source

Detection Logic

inbound_outbound and fd.l4proto=udp and not expected_udp_traffic

Field Validations

Loading…

Comments (0)

Loading comments...