Hello guys,
I'm receiving a lot of IPS alerts with SID 57103 for diferent destination IPs.
2021:12:17-10:29:25 sg-alpex snort[25704]: id="2101" severity="warn" sys="SecureNet" sub="ips" name="Intrusion protection alert" action="drop" reason="OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt" group="110" srcip="2.22.80.144" dstip="10.0.0.3" proto="6" srcport="80" dstport="4493" sid="57103" class="Attempted User Privilege Gain" priority="1" generator="1" msgid="0"
2021:12:17-10:30:30 sg-alpex snort[25704]: id="2101" severity="warn" sys="SecureNet" sub="ips" name="Intrusion protection alert" action="drop" reason="OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt" group="110" srcip="2.22.80.144" dstip="10.0.0.101" proto="6" srcport="80" dstport="60842" sid="57103" class="Attempted User Privilege Gain" priority="1" generator="1" msgid="0"
2021:12:17-10:30:39 sg-alpex snort[25704]: id="2101" severity="warn" sys="SecureNet" sub="ips" name="Intrusion protection alert" action="drop" reason="OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt" group="110" srcip="2.22.80.144" dstip="10.0.0.4" proto="6" srcport="80" dstport="4519" sid="57103" class="Attempted User Privilege Gain" priority="1" generator="1" msgid="0"
2021:12:17-10:42:47 sg-alpex snort[25704]: id="2101" severity="warn" sys="SecureNet" sub="ips" name="Intrusion protection alert" action="drop" reason="OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt" group="110" srcip="2.22.80.144" dstip="10.0.0.68" proto="6" srcport="80" dstport="52597" sid="57103" class="Attempted User Privilege Gain" priority="1" generator="1" msgid="0"
2021:12:17-10:44:03 sg-alpex snort[25704]: id="2101" severity="warn" sys="SecureNet" sub="ips" name="Intrusion protection alert" action="drop" reason="OS-WINDOWS Microsoft Windows Win32k elevation of privilege attempt" group="110" srcip="2.22.80.144" dstip="10.0.0.68" proto="6" srcport="80" dstport="52628" sid="57103" class="Attempted User Privilege Gain" priority="1" generator="1" msgid="0"

- 92.122.173.201
- 104.90.1.165
- 104.89.253.165
- 104.89.245.166
This thread was automatically locked due to age.