rules - snort arp scan detection -
hi new snort , simulated arp scan attack. trying detect attack in snort. no preprocessors detected attack wanted write rule it. find out snort rule not support arp protocol.
this scan sending arp request on possible addresses subnet 192.168.92.0/24 , waits answer means host up. possible detect these attack using snort rules?
here example of scan wireshark.
Comments
Post a Comment