Abnormal number of connections on SMB or NetBIOS ports
Last updated on:
In this page
About the rule
Rule Type
Advanced
Rule Description
Increased number of connections on SMB or NetBIOS ports may be indicative of a malicious entity attempting to exploit SMB vulnerabilities.
Severity
Trouble
Rule Requirement
Criteria
abnormal_number_of_connections_on_smb_or_netbios_ports_e1: DEST_PORT in (445,137,138,139) | groupby SOURCE_IP having count > 100 | last 1 DEST_PORT, DEST_IP select abnormal_number_of_connections_on_smb_or_netbios_ports_e1.SOURCE_IP as Source_IP, abnormal_number_of_connections_on_smb_or_netbios_ports_e1.SOURCE_IP.DEST_IP as Top_Destination_IP, abnormal_number_of_connections_on_smb_or_netbios_ports_e1.SOURCE_IP.DEST_PORT as Top_Destination_Port, count(abnormal_number_of_connections_on_smb_or_netbios_ports_e1.SOURCE_IP) as Total_Matched_Count
Detection
Execution Mode
scheduled
Log Sources
Network


