Skip to content

Latest commit

 

History

History
49 lines (42 loc) · 2.15 KB

THRESHOLD-S00079.md

File metadata and controls

49 lines (42 loc) · 2.15 KB

Rules: Inbound Port Scan

Description

This rule detects port scanning activity from external actors against public facing assets.

Additional Details

Detail Value
Type Threshold
Category Discovery
Apply Risk to Entities dstDevice_ip, dstDevice_hostname
Signal Name Inbound Port Scan
Summary Expression External port scan from IP: {{srcDevice_ip}} detected
Threshold Count 20
Threshold Window 5m
Score/Severity Static: 0
Enabled by Default False
Prototype False
Tags _mitreAttackTactic:TA0043, _mitreAttackTechnique:T1595, _mitreAttackTechnique:T1595.001, _mitreAttackTechnique:T1595.002

Vendors and Products

Fields Used

Origin Field
Normalized Schema dstDevice_hostname
Normalized Schema dstDevice_ip
Normalized Schema dstPort
Normalized Schema objectType
Normalized Schema srcDevice_ip_isInternal