This is an actual email.
Names have not been posted to protect the innocent.
"Looking for some information on the rule below. I'm not exactly sure what
it is looking for, but it seems to me that anything in SMTP_SERVES to
everything but HOME_NET with the syn flag set to a destination on port 25
will trigger this, it that correct? I am receiving a lot of noise form
this, but looking at the packet information, there's nothing there. I'm
really concerned with this type of alert because some of our exchange
servers are sending tcp syn's to destinations they should not send to,
i.e. other countries. Can I get some clarification on this specific rule?
I can't understand why an exchange server would send this type of data
unless it is also sending emails as well."
Over the past several years my job here at Cisco Talos has changed drastically. I took on new roles, which is awesome and exciting, but in ...
Without going off the deep-end here and discussing every single Snort rule keyword, I just wanted to touch on a few modifiers that people so...
Let me start off by saying I'm not bashing the writer of this article, and I'm trying not to be super critical. I don't want to...
1. I don't feel like I have much to say. I do a tremendous amount of writing and blogging on the Snort, ClamAV, and Talos blogs. So...