This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

ATP Alerts every 4 - 8 mins.

For the last three hours I have been getting ATP Alerts every 4 - mins.  The trouble is that the source IP keeps changing.  Here is an example.

 

Message........: BROWSER-IE Microsoft Edge App-v vbs command attempt

Details........: https://www.snort.org/search?query=48053

Time...........: 2020-05-12 15:07:12

Packet dropped.: yes

Priority.......: high

Classification.: Attempted User Privilege Gain IP protocol....: 6 (TCP)

 

Source IP address: 23.40.196.9 (a23-40-196-9.deploy.static.akamaitechnologies.com)

Source port: 80 (http)

Destination IP address: 192.168.15.18

Destination port: 53492

 

The internal IP is one of our domain controllers.  I have checks the logs on the DC's but don't see anything.

 

Any ideas?



This thread was automatically locked due to age.