Back to Rule

Rule History

SID: 2017162 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 3Jul 17, 2013, 12:00 PM

ET SCAN SipCLI VOIP Scan

alert udp $EXTERNAL_NET any -> $HOME_NET 5060 (msg:"ET SCAN SipCLI VOIP Scan"; content:"|0D 0A|User-Agent|3A 20|sipcli/"; fast_pattern; threshold: type limit, count 1, seconds 60, track by_src; reference:url,www.yasinkaplan.com/SipCli/; classtype:attempted-recon; sid:2017162; rev:3; metadata:created_at 2013_07_17, confidence Medium, signature_severity Informational, updated_at 2019_10_08;)

Jul 17, 2013, 12:00 PM

Oct 8, 2019, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-scan.rules