IIS FTP server Privileged Command Execution Anomaly
Last updated on:
In this page
About the rule
Rule Type
Anomaly
Rule Description
Detects unusual or potentially malicious sequences of FTP commands on an IIS server, which may indicate brute-force attempts, command injection, or abuse of FTP functionality.
Severity
Attention
Rule Requirement
Criteria
Action1: actionname = "iis_ftp_bad_sequence_of_cmd_executed" | isanomalous(User at an unusual Time) | isanomalous(User with abnormal Count) select Action1.CS_USERNAME,Action1.SC_STATUS,Action1.S_PORT,Action1.S_IP,Action1.C_IP,Action1.CLIENT_USER_NAME,Action1.STATUS,Action1.PORT,Action1.CLIENTIP
Detection
Execution Mode
Intelligent
Log Sources
Miscellaneous


