LoFP LoFP / t1573

t1573

TitleTags
false positives may be present if the organization works with international businesses. filter as needed.
legitimate administrative script
some networks may utilize these protocols but usage that is unfamiliar to local network administrators can be unexpected and suspicious. because this port is in the ephemeral range, this rule may false under certain conditions, such as when an application server with a public ip address replies to a client which has used a udp port in the range by coincidence. this is uncommon but such servers can be excluded.
unknown
user using a vpn or proxy