IDH - Play - ssh

This commit is contained in:
Josh Brower
2022-02-21 16:43:26 -05:00
parent 05be776f4b
commit eea2b9ccfd

View File

@@ -0,0 +1,18 @@
title: SO IDH - SSH Accessed
status: experimental
description: Detects when the SSH service on a SO IDH node has been probed.
author: Security Onion Solutions
logsource:
product: idh
detection:
selection:
event.code:
- 4000
- 4001
- 4002
condition: selection
falsepositives:
- None
fields:
- source.ip
level: critical