Sagan high stable other

[ARTILLERY] FTP brute force violation

[ARTILLERY] FTP brute force violation

View Source

Detection Logic

alert any $EXTERNAL_NET any -> $HOME_NET any (msg:"[ARTILLERY] FTP brute force violation"; content: "FTP brute forcing"; xbits: set, brute_force ,track ip_src, expire 21600; xbits: set, honeypot,track ip_src, expire 21600; default_proto: tcp; default_dst_port: $FTP_PORT; classtype: brute-force; parse_src_ip: 1; program: Artillery; reference: url,www.trustedsec.com/downloads/artillery; sid:5002081; rev:9;)

Field Validations

Loading…

Comments (0)

Loading comments...