Abnormal number of connections on SMB or NetBIOS ports

Last updated on:

About the rule

Rule Type

Advanced

Rule Description

Increased number of connections on SMB or NetBIOS ports may be indicative of a malicious entity attempting to exploit SMB vulnerabilities.

Severity

Trouble

Rule Requirement

Criteria

abnormal_number_of_connections_on_smb_or_netbios_ports_e1: DEST_PORT in (445,137,138,139) | groupby SOURCE_IP having count > 100 | last 1 DEST_PORT, DEST_IP select abnormal_number_of_connections_on_smb_or_netbios_ports_e1.SOURCE_IP as Source_IP, abnormal_number_of_connections_on_smb_or_netbios_ports_e1.SOURCE_IP.DEST_IP as Top_Destination_IP, abnormal_number_of_connections_on_smb_or_netbios_ports_e1.SOURCE_IP.DEST_PORT as Top_Destination_Port, count(abnormal_number_of_connections_on_smb_or_netbios_ports_e1.SOURCE_IP) as Total_Matched_Count

Detection

Execution Mode

scheduled

Log Sources

Network