# Edit Telnet port Activity rule

**URL:** <https://discuss.elastic.co/t/edit-telnet-port-activity-rule/267061>\
**Category:** SIEM\
**Tags:** detection-rules\
**Created:** [March 12, 2021, 9:04am UTC](https://discuss.elastic.co/t/edit-telnet-port-activity-rule/267061 "2021-03-12T09:04:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ethical20](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethical20/32/68123_2.png) [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Post date:** [March 12, 2021, 9:04am UTC](https://discuss.elastic.co/t/edit-telnet-port-activity-rule/267061/1 "2021-03-12T09:04:19Z")

</div>

Hi,

The Telnet Port Activity detection rule triggers whenever there is port scan / activity is tried Even if the port is closed

How can I edit the below rule to trigger ONLY if port is open?

```auto
event.category:(network or network_traffic) and network.transport:tcp and destination.port:23

```

Any help is apprectiated.

Regards,

---

<div class="post-metadata">

**Author:** ![variable](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/variable/32/118277_2.png) [@variable](https://discuss.elastic.co/u/variable)\
**Post date:** [March 17, 2021, 8:10pm UTC](https://discuss.elastic.co/t/edit-telnet-port-activity-rule/267061/2 "2021-03-17T20:10:34Z")

</div>

Thanks, @ethical20. Great observation.

Unfortunately, [Packetbeat doesn't have a protocol analyzer for Telnet](https://www.elastic.co/guide/en/beats/packetbeat/current/configuration-protocols.html).

I think the [rule](https://github.com/elastic/detection-rules/blob/main/rules/network/command_and_control_telnet_port_activity.toml) you're looking at is to identify Telnet Port Activity vs. Telnet authentication, because there isn't an analyzer.

As a workaround, you could use the rule to just look at your own IP ranges, to identify lateral movement vs. as an entry point from interfaces that are Internet-connected. You could do this using the Exception Framework in the Detection Engine.

 ![Pasted_Image_3_17_21__2_56_PM](https://us1.discourse-cdn.com/elastic/original/3X/0/b/0b079ae3d243a71bf6edf83ce18ef3338173d549.png)

This exception means the alert would only trigger when the source IP addresses are RFC1918 addresses. The wording is a bit confusing, a double-negative. The way I read it is if you used the "is" Operator, the rule would always trigger except when the IP addresses are RFC1918, so try the "is not" Operator. If that doesn't give you the expected response (only alert on internal Telnet), you can try it with the "is" Operator.

---

<div class="post-metadata">

**Author:** ![ethical20](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ethical20/32/68123_2.png) [@ethical20](https://discuss.elastic.co/u/ethical20)\
**Post date:** [March 22, 2021, 10:04am UTC](https://discuss.elastic.co/t/edit-telnet-port-activity-rule/267061/3 "2021-03-22T10:04:47Z")

</div>

Thanks @variable

I've got your point.

Regards,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 19, 2021, 10:05am UTC](https://discuss.elastic.co/t/edit-telnet-port-activity-rule/267061/4 "2021-04-19T10:05:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
