Question: 1 . Write snort rules for the following requirements ( one rule per requirement ) : a . Generate an alert on TCP comms. ,
Write snort rules for the following requirements one rule per requirement:
a Generate an alert on TCP comms. from any source IP and port to any destination IP on port The alert should display the following message: SSLTLS communications to a port. You can use the following SID:
b Generate an alert on IP comms. From any source IP and port to the following destination IP: on any port. The alert should display the following message: Connection attempts to Cobalt strike C server You can use the following SID:
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
