description-logoDescription

This indicates detection of a TCP packet with an abnormal flag setting.
TCP packets with the following bits set are considered part of the reconnaissance activities used by attackers to facilitate other attacks:

  • Only FIN flag set
  • None of the control bits set
  • Both SYN and FIN flags set
  • All of the control bits(ACK, FIN, PSH, RST, SYN, and URG) set (XMAX Scan)
  • SYN, FIN, PSH and URG bits set (NMAP fingerprint)
  • FIN, PSH, URG and both reserved bits set (NMAP XMAS)

affected-products-logoAffected Products

Any unprotected system connected to the Internet is vulnerable to the attack.

Impact logoImpact

Protocol Anomaly: Attackers can gain system information to prepare for further attacks.

recomended-action-logoRecommended Actions

This signature's action can be set to "Block" to protect against this threat.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)