APP-DETECT -- Snort attempted to take unique patterns of traffic and match them to a known application pattern, to confirm whether traffic should be allowed or stopped. (For example, a Get request is usually an HTTP/web application exchange, perhaps Facebook Messenger or other instant messenger, etc.).
APP-DETECT Teamviewer remote connection attempt
This rule looks for periodic TCP heartbeats sent by TeamViewer.
Teamviewer sends out various heartbeats during its runtime. This catches those for the security awareness of the administrator.
Attacks/Scans seen in the wild
No known false positives
Cisco Talos Intelligence Group
No rule groups
None
No information provided
None
Tactic: Command and Control
Technique: Automated Exfiltration
For reference, see the MITRE ATT&CK vulnerability types here: https://attack.mitre.org