LoFP LoFP / t1498

t1498

TitleTags
legitimate any requests may trigger this search, however it is unusual to see a large volume of them under typical circumstances. you may modify the threshold in the search to better suit your environment.
none currently known
none.
this search might be prone to high false positives if dhcp snooping has been incorrectly configured or in the unlikely event that the dhcp server has been moved to another network interface.
this search might be prone to high false positives if dhcp snooping or arp inspection has been incorrectly configured, or if a device normally sends many arp packets (unlikely).
this search might be prone to high false positives if you have malfunctioning devices connected to your ethernet ports or if end users periodically connect physical devices to the network.
this search will return false positives for any legitimate traffic captures by network administrators.
this search will show false positives. the analyst must look for errors and a pointer indicating a malicious file.
unlikely