Question: build an indicator infall would Trigger wifen the life tusiffightfisc is fourto. Include ute llepaul and SHAI hash value found within your system. 2. Build

build an indicator infall would Trigger wifen the
build an indicator infall would Trigger wifen the life tusiffightfisc is fourto. Include ute llepaul and SHAI hash value found within your system. 2. Build an indicator that would trigger when a file 278,528 bytes in size OR if the file powerpoint. exe is run OR if the created Time/Date is 2019/09/05 20:14:13 UTC as well as (AND) the SHA1 hash value is D4DD71906D3FD4133BDA24417A5FAF407096A61F 3. Build an indicator that would trigger only when the registry key HKEY_LOCAL_MACHINE Software\\Microsoft\\Windows\\CurrentVersion\\Run and value matches "virus.msi" as well as a file named "virus.msi" is located at the filepath C:\\Temp. 4. Build a SNORT header that would reflect the following network metadata: Alert when any SSH traffic coming from any source address coming to IP 192 168.1.10 through any port. 5. Build a SNORT rule that would reflect the following network metadata: Log traffic when DNS traffic from any external address is coming to any internal address over any port. Alert with the message "Cisco IPV4 DoS". Reference the classtype "attempted-dos"

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Accounting Questions!