ICMP_DDOS Stacheldraht client check skillz

 

Code: p413

Severity: Warning

 

Description: This event is generated when a Stacheldraht agent attempts to contact a known handler.

Impact: This indicates that a Stacheldraht agent may exist on the source host and a handler may exist on the destination host.

Corrective: Perform proper forensic analysis on the suspected compromised host to discover the means of compromise. Rebuild a confirmed compromised host. Use a packet filtering firewall to block inappropriate traffic to the network to prevent hosts from being compromised.