Question: alert tcp $EXTERNAL _ NET any - > $HOME _ NET 5 8 0 0 : 5 8 2 0 ( msg: ET SCAN
alert tcp $EXTERNALNET any $HOMENET :msg:ET SCAN Potential VNC Scan ; flags:S; threshold: type both, track bysrc count seconds ; reference:url,doc.emergingthreats.net; classtype:attemptedrecon; sid:; rev:; metadata:createdat updatedat ;
Break down the Snort rule header and explain what this rule does.
What stage of the cyber kill chain does the alerted activity violate?
What kind of attack is indicated?
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
