|
|
|
|
|
by raesene6
3157 days ago
|
|
Do you think there's any benefit in reduced log noise making a serious attacker more obvious to SoC analysts? I.e. if I run SSH on 24956/TCP and start seeing attacks, it's a fair bet this is targeted (someone has taken the time to do 65K port scans, not common for untargeted attackers), so it's a stronger signal for the blue team to look at that activity more closely than the noise on 22/TCP. |
|