ManderVoronwe / soc-g3

1 stars 0 forks source link

[Medium] Detection de scan reseau #5

Closed Mobaka9 closed 11 months ago

Mobaka9 commented 11 months ago

SPL Query index=suricata | stats dc(dest_port) as num_dest_port dc(dest_ip) as num_dest_ip by src_ip | where num_dest_port >100 OR num_dest_ip >100