POLICY-OTHER --
POLICY-OTHER SMBv1 protocol detection attempt
This event is generated when network traffic that indicates POLICY-OTHER SMBv1 protocol detection attempt is being used. Impact: Possible policy violation. The use of POLICY-OTHER SMBv1 protocol detection attempt may be prohibited by corporate policy in some network environments. Details: This event indicates that the POLICY-OTHER SMBv1 protocol detection attempt is being used on the protected network. Ease of Attack: Simple.
This rule fires when SMBv1 is detected on the network.
No public information
No known false positives
Cisco Talos
No rule groups
None
No information provided
None
Tactic: Lateral Movement
Technique: Exploitation of Remote Services
For reference, see the MITRE ATT&CK vulnerability types here: https://attack.mitre.org