Question: 1 . Write snort rules for the following requirements ( one rule per requirement ) : a . Generate an alert on TCP comms. ,

1. Write snort rules for the following requirements (one rule per requirement):
a. Generate an alert on TCP comms. ,from any source IP and port to any destination IP on port 443. The alert should display the following message: SSL/TLS communications to a port. You can use the following SID: 51500516
b. Generate an alert on IP comms. From any source IP and port to the following destination IP: 41.72.33.103 on any port. The alert should display the following message: Connection attempts to Cobalt strike C2 server. You can use the following SID: 51500517

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!