nsacyber / ELITEWOLF

OT security monitoring #nsacyber
Other
582 stars 61 forks source link

Add SIMENS LOGO! bruteforce discovery rule. #7

Open biero-el-corridor opened 9 months ago

biero-el-corridor commented 9 months ago

Add SIMENS LOGO! bruteforce discovery rule: (raised when more than 5 tentative in less than 15 seconds is made).

Here is presented the way in which the identifications are made on this PLC.
https://github.com/jankeymeulen/siemens-logo-rest

We can see a bruteforce pattern using the "UAMLOGIN" or "UAMLOGIN" field and the "/AJAX" path.

Tested on live equipment.