Skip to content

Latest commit

 

History

History
42 lines (35 loc) · 1.59 KB

MATCH-S00558.md

File metadata and controls

42 lines (35 loc) · 1.59 KB

Rules: Potential Inbound VNC Traffic

Description

Observes for successful TCP traffic to default VNC ports or explicit VNC/RFB traffic detected

Additional Details

Detail Value
Type Templated Match
Category Unknown/Other
Apply Risk to Entities dstDevice_hostname, dstDevice_ip
Signal Name Potential Inbound VNC Traffic
Summary Expression Potential VNC traffic detected to IP: {{dstDevice_ip}} Host: {{dstDevice_hostname}}
Score/Severity Static: 1
Enabled by Default False
Prototype False
Tags _mitreAttackTactic:TA0008, _mitreAttackTechnique:T1021, _mitreAttackTechnique:T1021.005

Vendors and Products

Fields Used

Origin Field
Normalized Schema application
Normalized Schema dstDevice_hostname
Normalized Schema dstDevice_ip
Normalized Schema dstPort
Normalized Schema ipProtocol
Normalized Schema objectType
Normalized Schema srcDevice_ip_isInternal
Normalized Schema success