cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1107
Views
0
Helpful
4
Replies

IPS Signature for RDP Connects?

kylehughes
Level 1
Level 1

First off we're trying to phase out our snort box and move onto our under-used IPS that we got. I've been trying to match the snort alerts we get to alerts that IPS can give. The one that I haven't seen or didn't realize it was the one I wanted, was RDP connections.

Our current snort notifies us when there is a RDP connection from the VPN to a server. Is there a sig thats already built in that detects this or is it something that I might have to build. If it is the later, how would you go about creating a signature for that?

Thanks

4 Replies 4

abinjola
Cisco Employee
Cisco Employee

Using Custom Signature Wizard you need to create your own signature for this RDP traffic

elevin
Level 1
Level 1

Kyle -

Did you ever find (or write) a signature to detect RDP connections? I'm specifically looking to detect RDP connections over non-standards ports (similar to the SSH over non-standard ports signature that exists).

No I haven't, but that project has semi been put on the back burner. I will try and update the thread if we figure out a sig

Hi Kyle,

Try to use Below link to search specific signature you want .

http://tools.cisco.com/security/center/search.x

Regards

Ritesh Malviya

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card