Brute Force HTTPS Server

You might also like

Download as pdf or txt
Download as pdf or txt
You are on page 1of 2

12/13/22, 3:10 PM Offense

Offense 738

Magnitude Status Relevance 5 Severity 1 Credibility 2

Offense Type Event Name


Description Brute Force Login in Https Server
Event/Flow count 1 events and 0 flows in 1 categories

Source IP(s) 10.10.61.189 Start Dec 13, 2022, 2:48:42 PM

Destination IP(s) 10.10.61.251  (10.10.61.251) Duration 13s

Network(s) Air-Gapped.Branches Assigned to Unassigned

Offense Source Summary

Event Name Brute Force Login in Https Server

High Level Category Access Low Level Category Access Denied

Severity 1

Offenses 1 Events/Flows 1

Last 5 Notes

Notes Username Creation Date

No results were returned.

Last 5 Search Results

Magnitude Started On Ended On Duration Events/Flows

No results were returned.

Top 5 Source IPs


Last
Source IP Magnitude Location Vulnerability User MAC Weight Offenses Destination(s) Events/Flows
Event/Flow
Unknown
10.10.61.189  Air-Gapped.Branches No Unknown 0 9 100 9m 55s 57,783
NIC

Top 5 Destination IPs


Last
Destination IP Magnitude Location Vulnerability Chained User MAC Weight Offenses Source(s) Events/Flows
Event/Flow
 Air- Unknown
10.10.61.251 No No root 0 5 3 21m 39s 15
Gapped.Branches NIC

Top 5 Log Sources

Name Description Group Events Offenses Total Events


Custom Rule Engine-8 :: Qradar Custom Rule Engine 1 637 47,818

Top 5 Users

https://10.10.30.84/console/qradar/jsp/QRadar.jsp 1/2
12/13/22, 3:10 PM Offense

Name Events/Flows Offenses Total Events/Flows


testbruteforce 1 2 4

Top 5 Categories

Name Magnitude Local Destination Count Events/Flows First Event/Flow Last Event/Flow    
Access Denied 1 1 Dec 13, 2022, 2:48:55 PM Dec 13, 2022, 2:48:55 PM

Last 10 Events

Event Name Magnitude Log Source Category Destination Destination IPv6 Dst Port Time
Brute Force Login in Https Custom Rule Engine-8 :: Dec 13, 2022,
Access Denied 10.10.61.251 0:0:0:0:0:0:0:0 0
Server Qradar 2:48:55 PM

Last 10 Flows

Application Source IP Source IPv6 Source Port Destination IP Destination IPv6 Destination Port Total Bytes Last Packet Time

No results were returned.

Top 5 Annotations

Annotation Time Weight


Dec 13, 2022,
"CRE Event".  CRE Rule description:  [Brute Force Login in Https Server] Brute Force Login in Https Server 6
2:49:08 PM
Dec 13, 2022,
"Offense Chaining".  This source IP currently has 4 other source active on the network. 1
3:01:11 PM
[Brute Force Login in Https Server] "Offense Renamed".  This offense has been renamed to "Brute Force Login in Https Server" by user request, based on an Event
Dec 13, 2022,
Rule that has fired.  Typically this is done because a particular sequence of recognizable and important security events has been detected, and the offense has been 1
2:49:08 PM
named accordingly.

https://10.10.30.84/console/qradar/jsp/QRadar.jsp 2/2

You might also like