Skip to content

[RTA] Add RTA for Default Telnet Port Connection#31

Merged
eric-forte-elastic merged 3 commits intomainfrom
default_telnet
Feb 25, 2026
Merged

[RTA] Add RTA for Default Telnet Port Connection#31
eric-forte-elastic merged 3 commits intomainfrom
default_telnet

Conversation

@eric-forte-elastic
Copy link
Contributor

Summary

This PR adds an RTA for the SIEM rule "Accepted Default Telnet Port Connection" (34fde489-94b0-4500-a76f-b8a157cf9269) to resolve the no_rta coverage/validation failures in elastic/detection-rules #5737.

The RTA creates an accepted TCP connection to localhost:23 and supports Windows, Linux, and macOS via a threaded listener + client.

Copy link
Contributor

@Mikaayenson Mikaayenson left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

couple nits, otherwise lgtm

@eric-forte-elastic eric-forte-elastic merged commit 7f67549 into main Feb 25, 2026
5 checks passed
@eric-forte-elastic eric-forte-elastic deleted the default_telnet branch February 25, 2026 16:49
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants