mitre-attack / car

Cyber Analytics Repository
Apache License 2.0
895 stars 304 forks source link

Cyware Submission - Added changes to CAR 2021-01-001 #92

Closed kp625544 closed 3 years ago

ikiril01 commented 3 years ago

@kp625544 thanks!

ikiril01 commented 3 years ago

@kp625544 we had a few more questions on this one:

It says the source is firewall logs and the destination is an internal IP, so I'm presuming you're looking for external to internal scans blocked by the firewall?

Also, what time range did you have in mind? If you're doing internal scan detection with passive network monitoring over a long enough timespan things like arbitrary port usage from protocols like RPC is going to cause a ton of false positives.