<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Intrusion_detection — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/intrusion_detection/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 28 May 2026 17:44:03 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/intrusion_detection/feed.xml" rel="self" type="application/rss+xml"/><item><title>Cisco Secure Firewall - High Volume of Intrusion Events Per Host</title><link>https://feed.craftedsignal.io/briefs/2026-05-cisco-high-intrusion-events/</link><pubDate>Thu, 28 May 2026 17:44:03 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-05-cisco-high-intrusion-events/</guid><description>This analytic detects internal systems generating an unusually high volume of intrusion detections within a 30-minute window using Cisco Secure Firewall Threat Defense logs, identifying hosts triggering more than 15 Snort-based signatures, which may indicate suspicious activity like malware execution, command-and-control communication, vulnerability scanning, or lateral movement.</description><content:encoded><![CDATA[<p>This analytic detects internal systems generating an unusually high volume of intrusion detections within a 30-minute window. It leverages Cisco Secure Firewall Threat Defense logs, specifically focusing on the IntrusionEvent event type, to identify hosts that trigger more than 15 Snort-based signatures during that time. A sudden spike in intrusion alerts originating from a single host may indicate suspicious or malicious activity such as malware execution, command-and-control communication, vulnerability scanning, or lateral movement. In some cases, this behavior may also be caused by misconfigured or outdated software repeatedly tripping detection rules. Systems exhibiting this pattern should be triaged promptly, as repeated Snort rule matches from a single source are often early indicators of compromise, persistence, or active exploitation attempts. The detection utilizes the Splunk Add-on for Cisco Security Cloud.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An attacker gains initial access to an internal system, potentially through phishing or exploiting a vulnerability.</li>
<li>The compromised system begins scanning the internal network for vulnerable services (T1595.002).</li>
<li>The vulnerability scanning triggers multiple Snort intrusion detection signatures on the Cisco Secure Firewall.</li>
<li>Malware executes on the compromised system, attempting to establish command and control communication (T1071).</li>
<li>The command and control communication generates network traffic patterns that match Snort signatures.</li>
<li>The attacker attempts lateral movement to other systems on the network (T1059).</li>
<li>Each attempt to move laterally triggers additional intrusion events.</li>
<li>The Cisco Secure Firewall logs these IntrusionEvent events, which are aggregated and analyzed by Splunk.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>A successful attack can lead to data exfiltration, system compromise, and disruption of services. A high volume of intrusion events originating from a single host may indicate that an attacker has gained a foothold within the network and is actively engaged in malicious activity. This can result in significant financial losses, reputational damage, and legal liabilities. The longer the attacker remains undetected, the greater the potential for damage.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Ensure the Cisco Secure Firewall Threat Defense is properly configured to log IntrusionEvent events as described in the <a href="https://www.cisco.com/c/en/us/td/docs/security/firepower/741/api/FQE/secure_firewall_estreamer_fqe_guide_740.pdf">Cisco documentation</a>.</li>
<li>Install and configure the Splunk Add-on for Cisco Security Cloud to ingest the Cisco Secure Firewall Threat Defense logs.</li>
<li>Deploy the Sigma rule <code>Cisco Secure Firewall - High Volume of Intrusion Events Per Host</code> to your Splunk environment and tune the threshold (TotalEvents &gt;= 15) based on your environment.</li>
<li>Investigate any systems that trigger a high volume of intrusion events, focusing on potential malware infections, unauthorized access, and vulnerability scanning.</li>
<li>Use the provided drilldown searches to view the detection results and risk events associated with the source IP address.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">threat</category><category>network</category><category>intrusion_detection</category><category>anomaly_detection</category></item></channel></rss>