Firewall Rule Accepting Cleartext Protocol Ports

Alerts on firewall-allowed traffic to common service ports that may carry credentials over unencrypted channels.

FreeReviewedSigma · Low · v2
Category
firewall
Author
Alexandr Yampolskyi, SOC Prime, Tim Shelton (SigmaHQ), DRL 1.1
Published
2019-03-26
Updated
2026-07-31

What it detects

This rule flags firewall traffic where connections to common cleartext and plaintext service ports are allowed (by actions such as accept/forward or action value 2). Attackers may use these exposed ports to capture credentials, perform session interception, or interact with services without encryption. It relies on firewall logs that record destination ports and the firewall action taken for those flows.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.