Hi all,
I am trying to create an alarm that trigger whenever suspicious events occur towards the RDP port (3389)
The problem is the following:
for other customers we use Qradar, and the rule, in addition to destination port 3389, also includes:
same source
same destination
7 events
within 10 minutes
I can't understand how I can put these last rules into McAfee. I can't find the way, I tried with the correlation rules, but it doesn't work. Do you think there is a possible method to solve my problem?
Thanks in advance
Solved! Go to Solution.
This can definitely be done through a correlation rule. In the correlation rule configuration group by source ip, destination ip to ensure the events all have the same source and destination.
In the filters add the destination port (3389), the signature IDs or normalisation IDs you expect it to match and any other filters as needed. In the properties of the logical element (for a single set of events any will do - if you are combining multiple events use the appropriate one) you can set the threshold and time window (7 events, 10 minutes).
This can definitely be done through a correlation rule. In the correlation rule configuration group by source ip, destination ip to ensure the events all have the same source and destination.
In the filters add the destination port (3389), the signature IDs or normalisation IDs you expect it to match and any other filters as needed. In the properties of the logical element (for a single set of events any will do - if you are combining multiple events use the appropriate one) you can set the threshold and time window (7 events, 10 minutes).
Thank you so much for your help!
Have a good day 😄
That sounds like it should work - if you're getting behaviour that does not match your expectations, please raise a Service Request with details of the configured rule and the events which triggered it - we will investigate and identify what is happening.
Thanks for your reply. Where can i open a Service request?
Thank you
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA