Detection Logic
alert any $EXTERNAL_NET any -> any $HOME_NET (msg:"[OKTA] BRUTE FORCE ATTEMPT [1]"; content: "Authentication failed: "; content:"user.authentication.auth_via_AD_agent"; xbits: set,brute_force,track ip_src, expire 21600; default_proto: tcp; default_dst_port: $SSH_PORT; classtype: brute-force; program: sshd; normalize; parse_src_ip: 1; parse_port; after: track by_src, count 10, seconds 300; threshold: type suppress, track by_src, count 1, seconds 300; reference:url, developer.okta.com/docs/reference/api/event-types/; sid: 5006604; rev:1;) Field Validations
Loading…
Comments (0)
Loading comments...