-
Accepted Default Telnet Port Connection
Sep 21, 2026 · Domain: Endpoint Use Case: Threat Detection Tactic: Command and Control Tactic: Lateral Movement Tactic: Initial Access Data Source: Fortinet Data Source: PAN-OS Data Source: pfSense Data Source: SonicWall Data Source: Suricata Resources: Investigation Guide Noise: High Performance: Normal Profile: Aggressive Rule Type: Custom Query (KQL) Domain: Network Data Source: Network Packet Capture Data Source: SonicWall Firewall Logs ·This rule detects network events that may indicate the use of Telnet traffic. Telnet is commonly used by system administrators to remotely control older or embedded systems using the command line shell. It should almost never be directly exposed to the Internet, as it is frequently targeted and exploited by threat actors as an initial access or backdoor vector. As a plain-text protocol, it may also expose usernames and passwords to anyone capable of observing the traffic.
Read More -
Identifies a successful SonicWall VPN- or WAN-zone administrator or remote-user login from a source IP that was not previously observed with the same user on the same appliance during the prior 14 days. This may indicate stolen credentials, compromised administrator access, or unauthorized remote access.
Read More -
Multiple SonicWall Login Failures Followed by Successful Login
Sep 19, 2026 · Domain: Network Domain: Identity Use Case: Threat Detection Use Case: Identity and Access Audit Tactic: Credential Access Tactic: Initial Access Data Source: SonicWall Resources: Investigation Guide Noise: Unknown Performance: Fast Rule Type: ES|QL Data Source: SonicWall Firewall Logs ·Identifies multiple failed SonicWall authentication attempts against several user accounts from one source IP, followed by a successful remote-access login from the same source to the same appliance. This may indicate successful password spraying, credential stuffing, or password guessing.
Read More