Network Scans Count By Destination Port

level
status experimental

Detects many failed connection attempts to different ports or hosts

Known false-positives

  • Inventarization systems
  • Vulnerability scans
  • Penetration testing activity

Raw rule (edit)

title: Network Scans Count By Destination Port
id: fab0ddf0-b8a9-4d70-91ce-a20547209afb
status: experimental
description: Detects many failed connection attempts to different ports or hosts
author: Thomas Patzke
date: 2017/02/19
modified: 2021/09/21
logsource:
    category: firewall
tags:
    - attack.discovery
    - attack.t1046
detection:
    selection:
        action: denied
    timeframe: 24h
    condition: selection | count(dst_port) by src_ip > 10
falsepositives:
    - Inventarization systems
    - Vulnerability scans
    - Penetration testing activity
level: medium
fields:
    - src_ip
    - dst_ip
    - dst_port

Sponsored by

Phish Report logo
With Phish Report you can achieve streamlined phishing takedowns using your existing security team.