SEVERITY | DATE | RULE NAME | EVENTID | TYPE | ||
---|---|---|---|---|---|---|
Medium | Mar, 07, 2024, 11:44 AM | SOC176 - RDP Brute Force Detected | 234 | Brute Force | ||
EventID : 234 Event Time : Mar, 07, 2024, 11:44 AM Rule : SOC176 - RDP Brute Force Detected Level : Security Analyst Source IP Address : 218.92.0.56 Destination IP Address : 172.16.17.148 Destination Hostname : Matthew Protocol : RDP Firewall Action : Allowed Alert Trigger Reason : Login failure from a single source with different non existing accounts Show Hint |
Value | Comment | Type |
---|---|---|
218[g]92.0.56 | Malicious IP | IP Address |
China | Malicious IP Location | E-mail Domain |