OpenCanary NTP Monlist Request Observed

Alerts when an OpenCanary node’s NTP service logs an NTP monlist request.

FreeReviewedSigma · High · v5
Product
opencanary
Category
application
Author
Security Onion Solutions (SigmaHQ), DRL 1.1
Published
2024-03-08
Updated
2026-07-31

ATT&CK techniques

Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule flags OpenCanary telemetry where an NTP service has logged an NTP monlist request. Attackers may use NTP monitoring/listing behavior to enumerate or probe time services, which can provide intelligence or lead to further abuse. It relies on OpenCanary application logs indicating the specific event type associated with monlist requests.

Related detections3 linkedT1498 — drag to rearrange
Malicious Simps Botnet Infection Marker File Creation (via file_event)
Kubernetes Deployment Deleted via Kubernetes API Audit Logs
Windows Process Command-Line Indicators of BlackByte Ransomware Activity
OpenCanary NTP Monlist Request Observed
Pivot detection · T1498 · 3 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.