Alert Name: Suspicious IP protocolAlert ID: [redacted]Severity: MediumSource: XDR Analytics BIOCCategory: Defense EvasionAction: DetectedDescription: The process has attempted to send an a packet with a 128bit IP address.
Uncategorized
1
Posts
1
Posters
3
Views
-
Alert Name: Suspicious IP protocol
Alert ID: [redacted]
Severity: Medium
Source: XDR Analytics BIOC
Category: Defense Evasion
Action: Detected
Description: The process has attempted to send an a packet with a 128bit IP address. This can only mean there is an integer overflow in an IPv4 address & is commonly used by attackers to circumvent your beautifully crafted IPv4 firewall ruleset.
Host: [redacted]