Sagan high stable other

[FORTINET-CORRELATED] Login accepted after recon activity

[FORTINET-CORRELATED] Login accepted after recon activity

View Source

Detection Logic

alert any $EXTERNAL_NET any -> $HOME_NET any (msg: "[FORTINET-CORRELATED] Login accepted after recon activity"; content: "32006 type="; content: "login"; meta_content: "%sagan%",accepted,successfully; parse_src_ip: 1; xbits: isset,recon,track ip_src; classtype: correlated-attack; threshold: type suppress, track by_src, count 5, seconds 3600; sid:5003265; rev:4;)

Field Validations

Loading…

Comments (0)

Loading comments...