Sagan critical stable other

[COURIER-CORRELATED] User login after exploit attempt

[COURIER-CORRELATED] User login after exploit attempt

View Source

Detection Logic

alert any $EXTERNAL_NET any -> $HOME_NET any (msg: "[COURIER-CORRELATED] User login after exploit attempt"; content: "LOGIN,"; parse_src_ip: 1; default_proto: tcp; classtype: successful-user; program: imapd
| imapd-ssl
| courierlogger; xbits: isset,exploit_attempt,track ip_src; threshold: type suppress, track by_src, count 5, seconds 3600; sid:5003251; rev:3;)

Field Validations

Loading…

Comments (0)

Loading comments...