Protocols passing authentication in cleartext (ASIM Network Session schema)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This hunting query identifies cleartext protocols like telnet, POP3, IMAP, and non-anonymous FTP that could leak sensitive information. These protocols may use SSL, but usually on different ports.

Attribute Value
Type Hunting Query
Solution Network Session Essentials
ID 96f9fdd1-bb5b-4d32-8790-666457dc00c0
Tactics CommandAndControl
Techniques T1071
Source View on GitHub

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Network Session Essentials