Suspicious Password Change Activity on IIS FTP Server

Last updated on:

About the rule

Rule Type

Anomaly

Rule Description

Detects unusual or potentially unauthorized password changes for FTP accounts on an IIS server, which may indicate account compromise or credential misuse.

Severity

Attention

Rule Requirement

Criteria

Action1: actionname = "iis_ftp_passwords_changed" | isanomalous(User at an unusual Time) | isanomalous(User with abnormal Count) select Action1.CS_USERNAME,Action1.SC_STATUS,Action1.S_PORT,Action1.S_IP,Action1.C_IP,Action1.CLIENT_USER_NAME,Action1.STATUS,Action1.PORT,Action1.CLIENTIP

Detection

Execution Mode

Intelligent

Log Sources

Miscellaneous