Vendor: Cisco

June 14, 2023 · View on GitHub

Product: Netflow

Use-Case: Compromised Credentials

RulesModelsMITRE ATT&CK® TTPsEvent TypesParsers
11111
Event TypeRulesModels
netflow-connectionT1046 - Network Service Scanning
A-NETFLOW-OsH-SweepScan-A: Abnormal for asset to access 20 assets in 10 seconds
A-NETFLOW-OsH-Scanners: Assets that access multiple assets within seconds in the organization