""ET INFO RDP - Response To External Host""

SID: 2001330

Revision: 10

Class Type: misc-activity

Metadata: attack_target Client_and_Server, created_at 2010_07_30, deployment Perimeter, performance_impact Significant, confidence Medium, signature_severity Informational, updated_at 2023_04_25, reviewed_at 2024_05_02

Reference:

Protocol: tcp

Source Network: $HOME_NET

Source Port: 3389

Destination Network: $EXTERNAL_NET

Destination Port: any

Flow: established,to_client

Contents:

  • Value: "|03|" Depth: 1 Offset: 0

  • Value: "|D0|" Depth: 1 Offset: 5

Within:

PCRE:

Special Options:

source