Skip to content
Threat Feed

Tag

Icmp

4 briefs RSS
low advisory

ICMP Timestamp or Information Request from the Internet

This brief identifies inbound ICMP Timestamp (type 13) or Information (type 15) requests originating from external IP addresses and targeting internal RFC1918 destinations, a legacy diagnostic activity commonly associated with host and path fingerprinting during reconnaissance, active scanning, or OS fingerprinting efforts by an unidentified actor, indicating a potential prelude to more severe attacks.

network_traffic integration network discovery reconnaissance icmp elastic
1r 2t
high advisory

Suspicious ICMP Redirect Messages from Internal Hosts Indicating MITM Activity

This brief details the detection of ICMP Redirect messages (IPv4 type 5, IPv6 type 137) originating from internal IP addresses, which strongly indicates Adversary-in-the-Middle (MITM) activity designed to manipulate routing, potentially leading to credential access or data exfiltration by directing target host traffic through a compromised internal system.

network-security credential-access mitm icmp
1r 1t
medium advisory

Detect Large ICMP Traffic

This analytic identifies ICMP traffic to external IP addresses with total bytes greater than 1,000 bytes, leveraging the Network_Traffic data model to detect potential information smuggling, covert communication, or command-and-control (C2) activities.

Palo Alto Network Traffic +4 network command-and-control icmp
2r 1t
medium advisory

CVE-2026-23398 ICMP NULL Pointer Dereference

CVE-2026-23398 is a vulnerability related to a NULL pointer dereference in the ICMP protocol, potentially leading to a denial-of-service condition in affected Microsoft products.

icmp denial-of-service vulnerability cve
2r 1t 1c