IMPORTANT: This documentation is no longer updated. Refer to Elastic's version policy and the latest documentation.

IPSEC NAT Traversal Port Activity

edit

This rule detects events that could be describing IPSEC NAT Traversal traffic. IPSEC is a VPN technology that allows one system to talk to another using encrypted tunnels. NAT Traversal enables these tunnels to communicate over the Internet where one of the sides is behind a NAT router gateway. This may be common on your network, but this technique is also used by threat actors to avoid detection.

Rule type: query

Rule indices:

  • auditbeat-*
  • filebeat-*
  • packetbeat-*
  • logs-endpoint.events.*

Severity: low

Risk score: 21

Runs every: 5m

Searches indices from: now-9m (Date Math format, see also Additional look-back time)

Maximum alerts per execution: 100

References: None

Tags:

  • Elastic
  • Host
  • Network
  • Threat Detection
  • Command and Control
  • Host

Version: 8

Rule authors:

  • Elastic

Rule license: Elastic License v2

Rule query

edit
event.category:(network or network_traffic) and network.transport:udp and destination.port:4500

Framework: MITRE ATT&CKTM