Back to Rule

Rule History

SID: 2001972 • Source: et/open

Versions (4)

Version DetailsCurrent

Rev: 21Jul 30, 2010, 12:00 PM

ET SCAN Behavioral Unusually fast Terminal Server Traffic Potential Scan or Infection (Inbound)

alert tcp $EXTERNAL_NET any -> $HOME_NET 3389 (msg:"ET SCAN Behavioral Unusually fast Terminal Server Traffic Potential Scan or Infection (Inbound)"; flow:not_established,to_server; flags: S,12; threshold: type both, track by_src, count 20, seconds 360; classtype:network-scan; sid:2001972; rev:21; metadata:created_at 2010_07_30, confidence Medium, signature_severity Informational, updated_at 2023_11_14;)

Jul 30, 2010, 12:00 PM

Nov 14, 2023, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-scan.rules