Question: alert tcp $EXTERNAL _ NET any - > $HOME _ NET 5 8 0 0 : 5 8 2 0 ( msg: ET SCAN

alert tcp $EXTERNAL_NET any -> $HOME_NET 5800:5820(msg:"ET SCAN Potential VNC Scan 5800-5820"; flags:S,12; threshold: type both, track by_src, count 5, seconds 60; reference:url,doc.emergingthreats.net/2002910; classtype:attempted-recon; sid:2002910; rev:5; metadata:created_at 2010_07_30, updated_at 2010_07_30;)
Break down the Snort rule header and explain what this rule does.
What stage of the cyber kill chain does the alerted activity violate?
What kind of attack is indicated?

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Databases Questions!