Suspicious Password Change Activity on IIS FTP Server
Last updated on:
In this page
About the rule
Rule Type
Anomaly
Rule Description
Detects unusual or potentially unauthorized password changes for FTP accounts on an IIS server, which may indicate account compromise or credential misuse.
Severity
Attention
Rule Requirement
Criteria
Action1: actionname = "iis_ftp_passwords_changed" | isanomalous(User at an unusual Time) | isanomalous(User with abnormal Count) select Action1.CS_USERNAME,Action1.SC_STATUS,Action1.S_PORT,Action1.S_IP,Action1.C_IP,Action1.CLIENT_USER_NAME,Action1.STATUS,Action1.PORT,Action1.CLIENTIP
Detection
Execution Mode
Intelligent
Log Sources
Miscellaneous


