CONTERX XDR Agent Brute-Force attack and NMAP scan detection.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

CONTERX XDR Agent Brute-Force attack and NMAP scan detection.

L0 Member

Hello !

 

Is it possible with CORTEX XDR Agent installed on Windows/Linux Server to detect:

 

- ssh/rdp/ftp and WEB apps brute force attack.

-NMAP scans.

 

Thanks in advance,

 

BR,

Max

1 accepted solution

Accepted Solutions

L5 Sessionator

Hi @M.Sorokins ,

 

Thank you for writing to live community!

 

While this forum is directed for cortex xdr related discussions, we do not have a specific capability endorsement or discussion that we generally cite. Cortex XDR definitely has UEBA based capabilities and network traffic detection capabilities based on telemetry collection. However, specific attack use cases require patterns and attack cycles which qualify as a MITRE ATT&CK lifecycle use case.  I would highly recommend reviewing this analytics reference for detailed insights on detection rules and encourage testing the specific use cases for validation.

 

Hope this helps

View solution in original post

2 REPLIES 2

L5 Sessionator

Hi @M.Sorokins ,

 

Thank you for writing to live community!

 

While this forum is directed for cortex xdr related discussions, we do not have a specific capability endorsement or discussion that we generally cite. Cortex XDR definitely has UEBA based capabilities and network traffic detection capabilities based on telemetry collection. However, specific attack use cases require patterns and attack cycles which qualify as a MITRE ATT&CK lifecycle use case.  I would highly recommend reviewing this analytics reference for detailed insights on detection rules and encourage testing the specific use cases for validation.

 

Hope this helps

Thanks !

>>Cortex XDR definitely has UEBA based capabilities and network traffic detection capabilities based on telemetry collection.

Yes. It could be done via XQL queries with traffic and events patterns. It's not TRUE NIDS, but it it works.

  • 1 accepted solution
  • 479 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!