@hal_pomeranz I also wonder whether they're monitoring external or internal.. stick an IDS outside the firewall and it'll go nuts. But that's like saying stand on a motorway and you'll get run over..
Top-level
@hal_pomeranz I also wonder whether they're monitoring external or internal.. stick an IDS outside the firewall and it'll go nuts. But that's like saying stand on a motorway and you'll get run over.. 2 comments
@tony Usually it means they finally started looking at their firewall logs for the first time. And they misinterpret every port scan as an active attack. |
@tony @hal_pomeranz also what is a "cyber attack"? I have seen people saying essentially 1 scan = 1 attack