IIS FTP server Privileged Command Execution Anomaly

Last updated on:

About the rule

Rule Type

Anomaly

Rule Description

Detects unusual or potentially malicious sequences of FTP commands on an IIS server, which may indicate brute-force attempts, command injection, or abuse of FTP functionality.

Severity

Attention

Rule Requirement

Criteria

Action1: actionname = "iis_ftp_bad_sequence_of_cmd_executed" | isanomalous(User at an unusual Time) | isanomalous(User with abnormal Count) select Action1.CS_USERNAME,Action1.SC_STATUS,Action1.S_PORT,Action1.S_IP,Action1.C_IP,Action1.CLIENT_USER_NAME,Action1.STATUS,Action1.PORT,Action1.CLIENTIP

Detection

Execution Mode

Intelligent

Log Sources

Miscellaneous