Sagan informational stable other
[COURIER-CORRELATED] Logout/disconnect after exploit attempt
[COURIER-CORRELATED] Logout/disconnect after exploit attempt
Detection Logic
alert any $EXTERNAL_NET any -> $HOME_NET any (msg: "[COURIER-CORRELATED] Logout/disconnect after exploit attempt"; meta_content: "%sagan%",LOGOUT,DISCONNECTED; default_proto: tcp; classtype: not-suspicious; parse_src_ip: 1; program: imapd
| imapd-ssl
| courierlogger; xbits: isset,exploit_attempt,track ip_src; threshold: type suppress, track by_src, count 5, seconds 3600; sid:5003247; rev:4;) Field Validations
Loading…
Comments (0)
Loading comments...