<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Seeing continous &amp;quot;Windows Account Locked&amp;quot; alert in Cisco IPS in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/seeing-continous-quot-windows-account-locked-quot-alert-in-cisco/m-p/1595677#M65530</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How are you seeing the events ? What are you using to check the events ?&amp;nbsp; IDM, IME ?&amp;nbsp; Send a screenshot the exact event. In the event details, there would be a signature id.&amp;nbsp; That signature id will tell us what the signature is designed to match on.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sid Chandrachud&lt;/P&gt;&lt;P&gt;Cisco TAC - Security team&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 04 Mar 2011 06:27:10 GMT</pubDate>
    <dc:creator>Siddharth Chandrachud</dc:creator>
    <dc:date>2011-03-04T06:27:10Z</dc:date>
    <item>
      <title>Seeing continous "Windows Account Locked" alert in Cisco IPS</title>
      <link>https://community.cisco.com/t5/network-security/seeing-continous-quot-windows-account-locked-quot-alert-in-cisco/m-p/1595675#M65526</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can any one have any idea on why we are seeing huge number of "Windows Account Locked" alert in Cisco IPS device towards only one Windows server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We checked whether Windows server is generating any malicious traffic by scanning the server but nothing is found&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0" class="MsoNormalTable" style="margin: auto auto auto -1.15pt; width: 829px; border-collapse: collapse; mso-yfti-tbllook: 1184; mso-padding-alt: 0in 0in 0in 0in;"&gt;&lt;TBODY&gt;&lt;TR style="height: 15pt; mso-yfti-irow: 0; mso-yfti-firstrow: yes;"&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 117.75pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="157"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Feb 23 2011 20:05:47&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 146.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="195"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Windows Account Locked&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 101.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="135"&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 85.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="114"&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 171.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="228"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Cisco Intrusion Prevention System&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 15pt; mso-yfti-irow: 1;"&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 117.75pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="157"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Feb 23 2011 20:05:32&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 146.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="195"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Windows Account Locked&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 101.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="135"&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 85.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="114"&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 171.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="228"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Cisco Intrusion Prevention System&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 15pt; mso-yfti-irow: 2;"&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 117.75pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="157"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Feb 23 2011 20:04:47&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 146.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="195"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Windows Account Locked&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 101.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="135"&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 85.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="114"&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 171.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="228"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Cisco Intrusion Prevention System&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 15pt; mso-yfti-irow: 3;"&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 117.75pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="157"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Feb 23 2011 20:04:32&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 146.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="195"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Windows Account Locked&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 101.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="135"&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 85.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="114"&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 171.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="228"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Cisco Intrusion Prevention System&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 15pt; mso-yfti-irow: 4;"&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 117.75pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="157"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Feb 23 2011 20:03:47&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 146.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="195"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Windows Account Locked&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 101.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="135"&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 85.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="114"&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 171.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="228"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Cisco Intrusion Prevention System&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 15pt; mso-yfti-irow: 5;"&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 117.75pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="157"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Feb 23 2011 20:03:32&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 146.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="195"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Windows Account Locked&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 101.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="135"&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 85.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="114"&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 171.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="228"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Cisco Intrusion Prevention System&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 15pt; mso-yfti-irow: 6;"&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 117.75pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="157"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Feb 23 2011 20:02:47&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 146.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="195"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Windows Account Locked&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 101.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="135"&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 85.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="114"&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 171.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="228"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Cisco Intrusion Prevention System&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;TR style="height: 15pt; mso-yfti-irow: 7; mso-yfti-lastrow: yes;"&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: windowtext 1pt solid; width: 117.75pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="157"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Feb 23 2011 20:02:32&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 146.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="195"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Windows Account Locked&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 101.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="135"&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 85.5pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="114"&gt;&lt;/TD&gt;&lt;TD style="border-right: windowtext 1pt solid; padding-right: 5.4pt; border-top: #ece9d8; padding-left: 5.4pt; padding-bottom: 0in; border-left: #ece9d8; width: 171.25pt; padding-top: 0in; border-bottom: windowtext 1pt solid; height: 15pt; background-color: transparent;" valign="bottom" width="228"&gt;&lt;P class="MsoNormal" style="margin: 0in 0in 0pt;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Calibri; "&gt;Cisco Intrusion Prevention System&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:17:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/seeing-continous-quot-windows-account-locked-quot-alert-in-cisco/m-p/1595675#M65526</guid>
      <dc:creator>mustafa.papdheen</dc:creator>
      <dc:date>2019-03-10T12:17:12Z</dc:date>
    </item>
    <item>
      <title>Re: Seeing continous "Windows Account Locked" alert in Cisco IPS</title>
      <link>https://community.cisco.com/t5/network-security/seeing-continous-quot-windows-account-locked-quot-alert-in-cisco/m-p/1595676#M65528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;do you have the signature ID?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Mar 2011 03:13:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/seeing-continous-quot-windows-account-locked-quot-alert-in-cisco/m-p/1595676#M65528</guid>
      <dc:creator>PAUL GILBERT ARIAS</dc:creator>
      <dc:date>2011-03-04T03:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: Seeing continous "Windows Account Locked" alert in Cisco IPS</title>
      <link>https://community.cisco.com/t5/network-security/seeing-continous-quot-windows-account-locked-quot-alert-in-cisco/m-p/1595677#M65530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How are you seeing the events ? What are you using to check the events ?&amp;nbsp; IDM, IME ?&amp;nbsp; Send a screenshot the exact event. In the event details, there would be a signature id.&amp;nbsp; That signature id will tell us what the signature is designed to match on.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sid Chandrachud&lt;/P&gt;&lt;P&gt;Cisco TAC - Security team&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Mar 2011 06:27:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/seeing-continous-quot-windows-account-locked-quot-alert-in-cisco/m-p/1595677#M65530</guid>
      <dc:creator>Siddharth Chandrachud</dc:creator>
      <dc:date>2011-03-04T06:27:10Z</dc:date>
    </item>
    <item>
      <title>Re: Seeing continous "Windows Account Locked" alert in Cisco IPS</title>
      <link>https://community.cisco.com/t5/network-security/seeing-continous-quot-windows-account-locked-quot-alert-in-cisco/m-p/1595678#M65531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for your response. When i lookup up further, Ciscp IPS vulnerability reference page :&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/security/center/viewIpsSignature.x"&gt;http://tools.cisco.com/security/center/viewIpsSignature.x&lt;/A&gt;&lt;SPAN&gt;?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Signature ID : signatureId=5605&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Target Port =445.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Papdheen M&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Mar 2011 08:48:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/seeing-continous-quot-windows-account-locked-quot-alert-in-cisco/m-p/1595678#M65531</guid>
      <dc:creator>mustafa.papdheen</dc:creator>
      <dc:date>2011-03-04T08:48:19Z</dc:date>
    </item>
    <item>
      <title>Re: Seeing continous "Windows Account Locked" alert in Cisco IPS</title>
      <link>https://community.cisco.com/t5/network-security/seeing-continous-quot-windows-account-locked-quot-alert-in-cisco/m-p/1595679#M65533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="data2"&gt;&lt;/SPAN&gt;Mustafa,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the signature details:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=5605&amp;amp;signatureSubId=0&amp;amp;softwareVersion=6.0&amp;amp;releaseVersion=S262"&gt;http://tools.cisco.com/security/center/viewIpsSignature.x?signatureId=5605&amp;amp;signatureSubId=0&amp;amp;softwareVersion=6.0&amp;amp;releaseVersion=S262&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="data2"&gt;This signature detects a Windows SMB user account&amp;nbsp; that has been locked on the Windows server due to multiple failed logon&amp;nbsp; attempts, via the "STATUS_ACCOUNT_LOCKED_OUT" message returned to the&amp;nbsp; client.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This signature severity is set by default to 'informational'&lt;/P&gt;&lt;P&gt;Hence all the signature is doing is leeting you know some users were locked out due to multiple logon attempts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The event details will also reveal victim ip which might be the machine on which the logon attempts were tried.&lt;/P&gt;&lt;P&gt;Let me know if this addresses your concern.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Sid&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 05 Mar 2011 19:16:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/seeing-continous-quot-windows-account-locked-quot-alert-in-cisco/m-p/1595679#M65533</guid>
      <dc:creator>Siddharth Chandrachud</dc:creator>
      <dc:date>2011-03-05T19:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: Seeing continous "Windows Account Locked" alert in</title>
      <link>https://community.cisco.com/t5/network-security/seeing-continous-quot-windows-account-locked-quot-alert-in-cisco/m-p/1595680#M65535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Sid,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your response. Actually attacker IP is a database server joined in domain and attacker username is showing as empty"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server is running with latest AV signature.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attacker IP - Database server(server itsefl)&lt;/P&gt;&lt;P&gt;Destination- Active Direcotry server&lt;/P&gt;&lt;P&gt;Destination Port - 445&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More information will be helpful to isolate the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Papdheen M&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 13 Mar 2011 10:51:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/seeing-continous-quot-windows-account-locked-quot-alert-in-cisco/m-p/1595680#M65535</guid>
      <dc:creator>mustafa.papdheen</dc:creator>
      <dc:date>2011-03-13T10:51:46Z</dc:date>
    </item>
  </channel>
</rss>

