Intrusion Prevention

IMAP.Login.Brute.Force

Description

This indicates a detection of at least 60 failed IMAP logins in 10 seconds which indicate a possible IMAP logins brute force attack.

Affected Products

All IMAP servers

Impact

Impact of a successful attack could vary, with the worse case being a system compromise.

Recommended Actions

Adjust the threshold to your network.
Monitor the traffic from that network for any suspicious activity.