Detecting Actors Activity with Threat Intel, (Fri, Dec 4th)

SANS Internet Storm Center, InfoCON: green 2020-12-04

Summary:

Over the past three weeks I have applied threat intel to all the inbound traffic going to my honeypot and the stats have shown some interesting trends. The top 20 TCP ports targeted have been between 1-50 and top 20 UDP 7-11211. During this period, the sensor recorded over 301K indicators matching threat intel from known actors.

Link:

https://isc.sans.edu/diary/rss/26848

From feeds:

Intel Hub ยป T01 - SANS Internet Storm Center, InfoCON: green

Tags:

Date tagged:

12/04/2020, 00:10

Date published:

12/03/2020, 22:30