APP-DETECT -- Snort attempted to take unique patterns of traffic and match them to a known application pattern, to confirm whether traffic should be allowed or stopped. (For example, a Get request is usually an HTTP/web application exchange, perhaps Facebook Messenger or other instant messenger, etc.).
APP-DETECT Teamviewer remote connection attempt
This rule listens for periodic UDP heardbeats sent by TeamViewer
Teamviewer contains unique patterns in its traffic. This rule helps to inform security operations that Teamviwer is in use on their network for awareness.
Attacks/Scans seen in the wild
No known false positives
Cisco Talos Intelligence Group
No rule groups
None
No information provided
None
Tactic: Command and Control
Technique: Custom Command and Control Protocol
For reference, see the MITRE ATT&CK vulnerability types here: https://attack.mitre.org