2012-02-27
12:58 PM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Example: Internet bound SMB attempts
Attached is a correlation rule (the logic anyway) for alerting on internet bound SMB accesses, which may be indicitive of malware or policy violation.
Keep in mind you may trigger lots of alerts initially. Customize as you need.
0 Replies
