🐾 - 🔔 Many TCP/SYN - Possible Masscan Network Service Discovery 🥷 - T1046

SID: 3321263Rev: 33 views
Sourcepawpatrules
CreatedMay 19, 2024
UpdatedMay 19, 2024
Classificationattempted-recon
alert tcp any any -> any any (msg:"🐾 - 🔔 Many TCP/SYN - Possible Masscan Network Service Discovery 🥷 - T1046"; flow:to_server; flags:S,2; threshold:type threshold, track by_src, count 1000, seconds 30; reference:url,https://attack.mitre.org/techniques/T1046/; reference:url,https://github.com/robertdavidgraham/masscan; metadata:created_at 2024_05_19, updated_at 2024_05_19, signature_severity Major, mitre_tactic_id TA0007, mitre_tactic_name Discovery, mitre_technique_id T1046, mitre_technique_name Network_Service_Discovery; sid:3321263; rev:3; classtype:attempted-recon;)

Metadata

created at2024_05_19
updated at2024_05_19
signature severityMajor
mitre tactic idTA0007
mitre tactic nameDiscovery
mitre technique idT1046
mitre technique nameNetwork_Service_Discovery

Comments (0)

Please sign in to leave a comment.
Sign in

No comments yet. Be the first to comment!