-
RPC (Remote Procedure Call) from the Internet
Sep 21, 2026 · Tactic: Initial Access Domain: Endpoint Use Case: Threat Detection Data Source: Corelight Data Source: Fortinet Data Source: Network Traffic Data Source: PAN-OS Data Source: pfSense Data Source: Zeek Resources: Investigation Guide Noise: High Performance: Normal Profile: Aggressive Rule Type: Custom Query (KQL) Domain: Network Data Source: Network Packet Capture ·This rule detects network events that may indicate the use of RPC traffic from the Internet. RPC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector.
Read More -
RPC (Remote Procedure Call) to the Internet
Sep 21, 2026 · Tactic: Initial Access Tactic: Lateral Movement Domain: Endpoint Use Case: Threat Detection Data Source: Corelight Data Source: Fortinet Data Source: PAN-OS Data Source: Network Traffic Data Source: pfSense Data Source: Zeek Resources: Investigation Guide Noise: High Performance: Normal Profile: Aggressive Rule Type: Custom Query (KQL) Domain: Network Data Source: Network Packet Capture ·This rule detects network events that may indicate the use of RPC traffic to the Internet. RPC is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector.
Read More -
SMB (Windows File Sharing) Activity from the Internet
Sep 21, 2026 · Tactic: Initial Access Domain: Network Use Case: Threat Detection Data Source: Corelight Data Source: Fortinet Data Source: PAN-OS Data Source: Network Traffic Data Source: pfSense Data Source: Zeek Resources: Investigation Guide Noise: Medium Performance: Normal Rule Type: New Terms Data Source: Network Packet Capture ·This rule detects network events that may indicate inbound Windows file sharing (SMB or CIFS) traffic originating from the Internet. SMB should never be directly reachable from the Internet, as it is a primary target for exploitation by threat actors seeking initial access. Inbound SMB from a public IP is a direct precondition for attacks such as EternalBlue (MS17-010) and related SMB remote code execution vulnerabilities.
Read More -
SMB (Windows File Sharing) Activity to the Internet
Sep 21, 2026 · Tactic: Initial Access Tactic: Exfiltration Domain: Network Use Case: Threat Detection Data Source: Corelight Data Source: Fortinet Data Source: PAN-OS Data Source: Network Traffic Data Source: pfSense Data Source: Zeek Resources: Investigation Guide Noise: High Performance: Normal Profile: Aggressive Rule Type: New Terms Data Source: Network Packet Capture ·This rule detects network events that may indicate the use of Windows file sharing (also called SMB or CIFS) traffic to the Internet. SMB is commonly used within networks to share files, printers, and other system resources amongst trusted systems. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector or for data exfiltration.
Read More -
Abnormally Large DNS Response
Sep 19, 2026 · Use Case: Threat Detection Tactic: Lateral Movement Tactic: Impact Resources: Investigation Guide Use Case: Vulnerability Data Source: Corelight Data Source: PAN-OS Data Source: Network Traffic Data Source: Zeek Noise: High Performance: Normal Profile: Aggressive Threat: Vulnerability Exploit Rule Type: Custom Query (KQL) Domain: Network Data Source: Network Packet Capture ·Specially crafted DNS requests can manipulate a known overflow vulnerability in some Windows DNS servers, resulting in Remote Code Execution (RCE) or a Denial of Service (DoS) from crashing the service.
Read More -
RDP (Remote Desktop Protocol) from the Internet
Sep 19, 2026 · Tactic: Command and Control Tactic: Lateral Movement Tactic: Initial Access Domain: Endpoint Use Case: Threat Detection Data Source: Corelight Data Source: PAN-OS Data Source: Network Traffic Data Source: pfSense Data Source: Zeek Resources: Investigation Guide Noise: High Performance: Normal Profile: Aggressive Rule Type: Custom Query (KQL) Domain: Network Data Source: Network Packet Capture ·This rule detects network events that may indicate the use of RDP traffic from the Internet. RDP is commonly used by system administrators to remotely control a system for maintenance or to use shared resources. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector.
Read More -
SMTP to the Internet on Port 26/TCP
Sep 19, 2026 · Tactic: Command and Control Tactic: Exfiltration Domain: Endpoint Use Case: Threat Detection Data Source: Corelight Data Source: Fortinet Data Source: PAN-OS Data Source: Network Traffic Data Source: pfSense Data Source: Zeek Resources: Investigation Guide Noise: High Performance: Normal Profile: Aggressive Rule Type: Custom Query (KQL) Domain: Network Data Source: Network Packet Capture ·This rule detects events that may indicate use of SMTP on TCP port 26 from an internal host to an external destination. This port is commonly used by several popular mail transfer agents to deconflict with the default SMTP port 25. This port has also been used by a malware family called BadPatch for command and control of Windows systems. The rule is scoped to outbound traffic (internal source to external destination) to focus on the command and control and exfiltration use cases, rather than benign internal mail relays or unrelated transit traffic observed by the sensor.
Read More