Skip to Main Content
Liongard Library

Welcome to Liongard Library, where Lions share! This is a community-led space where Liongard users can come to teach and learn from one another.
Share custom Metrics, get inspired and see what’s trending in the Pride.

Pride Etiquette:
➕ Have great custom Metrics? Add them as entries!
🌟 Want to use a Metric? Copy the query and
follow this doc.
👍 Tried a Metric from the Library? Like it!
📣 Have a question or feedback on a Metric? Add a comment!
🔎 Not sure where to start? Learn about Metrics and how to write them.
💬 Need help writing a metric or want to help support others? Join the conversation in our Liongard Lounge #metrics slack channel.


🥴 See something off? Open a support chat to let us know.

Categories SonicWall
Created by Devon
Created on Aug 9, 2021

Sonicwall: NAT contains RDS services

This one is a little trickier to catch but looks for the translated service containing RDP, RDS, Terminal, or 3389 with source being any. This is an indicator of wide open RDP however if the service does not contain these names it is missed.

Query

NATPolicies[?contains(TranslatedService, `RDP`) || contains(TranslatedService, 'RDS') || contains(TranslatedService, 'Terminal') || contains(TranslatedService, '3389') && contains(Source, 'any')].name

  • Attach files