Setzen Sie
Die Exploit-Kategorie enthält Ereignisse, bei denen ein Exploit bezüglich der Kommunikation oder des Zugriffs aufgetreten ist.
Die folgende Tabelle enthält eine Beschreibung der untergeordneten Ereigniskategorien sowie die zugehörigen Bewertungsstufen für die Exploit-Kategorie.
| Untergeordnete Ereigniskategorie | Kategorie-ID | Beschreibung | Bewertungsstufe (0 - 10) |
|---|---|---|---|
| Unbekannte Exploit-Attacke | 5001 | Zeigt eine unbekannte Exploit-Attacke an. | 9 |
| Pufferüberlauf | 5002 | Zeigt einen Pufferüberlauf an. | 9 |
| DNS-Exploit | 5003 | Zeigt ein DNS-Exploit an. | 9 |
| Telnet-Exploit | 5004 | Zeigt ein Telnet-Exploit an. | 9 |
| Linux® -Exploit | 5005 | Zeigt ein Linux -Exploit an | 9 |
| Unix-Exploit | 5006 | Zeigt ein UNIX-Exploit an. | 9 |
| Windows-Exploit | 5007 | Zeigt ein Exploit Microsoft Windows an. | 9 |
| E-Mail-Exploit | 5008 | Zeigt ein Mail-Server-Exploit an. | 9 |
| Infrastruktur-Exploit | 5009 | Zeigt ein Infrastruktur-Exploit an. | 9 |
| Sonstiges Exploit | 5010 | Zeigt ein sonstiges Exploit an. | 9 |
| Web-Exploit | 5011 | Zeigt ein Web-Exploit an. | 9 |
| Sitzungs-Hijack | 5012 | Zeigt an, dass in einer Sitzung in Ihrem Netz interveniert wurde. | 9 |
| Computerwurm aktiv | 5013 | Zeigt einen aktiven Computerwurm an. | 10 |
| Kennwort erraten/abrufen | 5014 | Zeigt an, dass ein Benutzer Zugriff auf seine Kennwortinformationen in der Datenbank angefordert hat. | 9 |
| FTP-Exploit | 5015 | Zeigt ein FTP-Exploit an. | 9 |
| RPC-Exploit | 5016 | Zeigt ein RPC-Exploit an. | 9 |
| SNMP-Exploit | 5017 | Zeigt ein SNMP-Exploit an. | 9 |
| NOOP-Exploit | 5018 | Zeigt ein NOOP-Exploit an. | 9 |
| Samba-Exploit | 5019 | Zeigt ein Samba-Exploit an. | 9 |
| SSH-Exploit | 5020 | Zeigt ein SSH-Exploit an. | 9 |
| Datenbank-Exploit | 5021 | Zeigt ein Datenbank-Exploit an. | 9 |
| ICMP-Exploit | 5022 | Zeigt ein ICMP-Exploit an. | 9 |
| UDP-Exploit | 5023 | Zeigt ein UDP-Exploit an. | 9 |
| Browser-Exploit | 5024 | Zeigt ein Exploit in Ihrem Browser an. | 9 |
| DHCP-Exploit | 5025 | Zeigt ein DHCP-Exploit an. | 9 |
| Fernzugriffs-Exploit | 5026 | Zeigt ein Fernzugriffs-Exploit an. | 9 |
| ActiveX-Exploit | 5027 | Zeigt ein Exploit durch eine ActiveX-Anwendung an. | 9 |
| SQL-Injektion | 5028 | Zeigt an, dass eine SQL-Injection aufgetreten ist. | 9 |
| Cross-Site Scripting | 5029 | Zeigt eine Cross-Site Scripting-Sicherheitslücke an. | 9 |
| Sicherheitslücke in Formatierzeichenfolge | 5030 | Zeigt eine Sicherheitslücke in der Formatierzeichenfolge an. | 9 |
| Eingabevalidierungs-Exploit | 5031 | Zeigt an, dass ein Versuch eines Eingabevalidierungs-Exploits erkannt wurde. | 9 |
| Remote-Code-Ausführung | 5032 | Zeigt an, dass ein Remote-Code-Ausführungsversuch erkannt wurde. | 9 |
| Datenverlust im Hauptspeicher | 5033 | Zeigt an, dass ein Exploit mit drohendem Datenverlust im Hauptspeicher erkannt wurde. | 9 |
| Befehlsausführung | 5034 | Zeigt an, dass eine Befehlsausführung über Fernzugriff erkannt wurde. | 9 |
| Codeinjektion | 5035 | Zeigt an, dass eine Codeinjektion erkannt wurde. | 9 |
| Attacke durch Nachrichtenaufzeichnung und -wiederholung | 5036 | Zeigt an, dass eine Attacke durch Nachrichtenaufzeichnung und -wiederholung erkannt wurde. | 9 |