POLICY-OTHER SSL/TLS weak RC4 cipher suite use attempt
This event is generated when a weak SSL/TLS RC4 cipher suite is detected.
Potential Corporate Privacy Violation
Ease of Attack:
What To Look For
This rule alerts when an attempt to enumerate weak cipher suites is being performed.
No public information
No known false positives
Cisco Talos Intelligence Group
MITRE ATT&CK Framework
Technique: Account Discovery
For reference, see the MITRE ATT&CK vulnerability types here:
CVE Additional Information
CVE-2015-2808The RC4 algorithm, as used in the TLS protocol and SSL protocol, does not properly combine state data with key data during the initialization phase, which makes it easier for remote attackers to conduct plaintext-recovery attacks against the initial bytes of a stream by sniffing network traffic that occasionally relies on keys affected by the Invariance Weakness, and then using a brute-force approach involving LSB values, aka the "Bar Mitzvah" issue.
||Ease of Access||