For the last three hours I have been getting ATP Alerts every 4 - mins. The trouble is that the source IP keeps changing. Here is an example.
Message........: BROWSER-IE Microsoft Edge App-v vbs command attempt
Details........: https://www.snort.org/search?query=48053
Time...........: 2020-05-12 15:07:12
Packet dropped.: yes
Priority.......: high
Classification.: Attempted User Privilege Gain IP protocol....: 6 (TCP)
Source IP address: 23.40.196.9 (a23-40-196-9.deploy.static.akamaitechnologies.com)
Source port: 80 (http)
Destination IP address: 192.168.15.18
Destination port: 53492
The internal IP is one of our domain controllers. I have checks the logs on the DC's but don't see anything.
Any ideas?
This thread was automatically locked due to age.