ET POLICY Outbound SMTP NTLM Authentication Observed
Sourceet/open
CreatedApril 4, 2019
UpdatedJuly 26, 2019
Classificationpolicy-violation
alert smtp $HOME_NET any -> $EXTERNAL_NET any (msg:"ET POLICY Outbound SMTP NTLM Authentication Observed"; flow:established,to_server; content:"AUTH|20|ntlm|20|"; depth:10; nocase; fast_pattern; pcre:"/^(?:[A-Z0-9+/]{4})*(?:[A-Z0-9+/]{2}==|[A-Z0-9+/]{3}=|[A-Z0-9+/]{4})$/Ri"; classtype:policy-violation; sid:2027152; rev:1; metadata:attack_target Client_and_Server, created_at 2019_04_04, deployment Perimeter, performance_impact Low, confidence High, signature_severity Minor, updated_at 2019_07_26;)
Metadata
attack targetClient_and_Server
created at2019_04_04
deploymentPerimeter
performance impactLow
confidenceHigh
signature severityMinor
updated at2019_07_26
Comments (0)
Please sign in to leave a comment.
Sign inNo comments yet. Be the first to comment!