Cluster details: [EXPLOIT] LSASS / DCE RPC exploit: Mainz/Bielefeld Shellcode (445/TCP)
|
The public dashboard only gives overall statistics about a cluster. Each cluster has a name, level of classification, port list on which the payload was seen, unique sources seen sending the payload, final signature size and final (“super”) signature computed over the cluster in snort format. This super signature is common to all the flows that formed the cluster, and is potentially the signature of a new threat such as an exploit or worm. |