- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
01-13-2025 07:53 AM
Hello !
Is it possible with CORTEX XDR Agent installed on Windows/Linux Server to detect:
- ssh/rdp/ftp and WEB apps brute force attack.
-NMAP scans.
Thanks in advance,
BR,
Max
01-15-2025 08:40 AM
Hi @M.Sorokins ,
Thank you for writing to live community!
While this forum is directed for cortex xdr related discussions, we do not have a specific capability endorsement or discussion that we generally cite. Cortex XDR definitely has UEBA based capabilities and network traffic detection capabilities based on telemetry collection. However, specific attack use cases require patterns and attack cycles which qualify as a MITRE ATT&CK lifecycle use case. I would highly recommend reviewing this analytics reference for detailed insights on detection rules and encourage testing the specific use cases for validation.
Hope this helps
01-15-2025 08:40 AM
Hi @M.Sorokins ,
Thank you for writing to live community!
While this forum is directed for cortex xdr related discussions, we do not have a specific capability endorsement or discussion that we generally cite. Cortex XDR definitely has UEBA based capabilities and network traffic detection capabilities based on telemetry collection. However, specific attack use cases require patterns and attack cycles which qualify as a MITRE ATT&CK lifecycle use case. I would highly recommend reviewing this analytics reference for detailed insights on detection rules and encourage testing the specific use cases for validation.
Hope this helps
01-15-2025 11:12 PM
Thanks !
>>Cortex XDR definitely has UEBA based capabilities and network traffic detection capabilities based on telemetry collection.
Yes. It could be done via XQL queries with traffic and events patterns. It's not TRUE NIDS, but it it works.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!