Cleartext Authentication via Netflow to Common Service Ports

Alerts on Netflow flows to specific service ports that may indicate cleartext protocol use and potential credential exposure.

FreeReviewedSigma · Low · v5
Service
netflow
Author
Alexandr Yampolskyi, SOC Prime (SigmaHQ), DRL 1.1
Published
2019-03-26
Updated
2026-07-31

What it detects

This rule flags network traffic observed in Netflow where the destination port matches a set of commonly used services that often host authentication or administrative access. Cleartext protocol use on these ports can expose usernames and authentication credentials to interception and credential replay. It relies on Netflow telemetry for destination port values to identify potentially unencrypted in-transit sessions.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.