Sagan critical stable other
[COURIER-CORRELATED] User login after exploit attempt
[COURIER-CORRELATED] User login after exploit attempt
Detection Logic
alert any $EXTERNAL_NET any -> $HOME_NET any (msg: "[COURIER-CORRELATED] User login after exploit attempt"; content: "LOGIN,"; parse_src_ip: 1; default_proto: tcp; classtype: successful-user; program: imapd
| imapd-ssl
| courierlogger; xbits: isset,exploit_attempt,track ip_src; threshold: type suppress, track by_src, count 5, seconds 3600; sid:5003251; rev:3;) Field Validations
Loading…
Comments (0)
Loading comments...