Files
securityonion/salt/idh/plays/idh_ftp.yml
T
2022-02-23 10:50:13 -05:00

17 lines
375 B
YAML

title: SO IDH - FTP Login Attempt
id: d2d82069-30a7-4ac3-b584-ba696fbc24fd
status: experimental
description: Detects when the FTP service on a SO IDH node has had a login attempt.
author: Security Onion Solutions
logsource:
product: idh
detection:
selection:
event.code:
- 2000
condition: selection
falsepositives:
- None
fields:
- source.ip
level: critical