Skip to content

Latest commit

 

History

History
51 lines (44 loc) · 2.23 KB

THRESHOLD-S00080.md

File metadata and controls

51 lines (44 loc) · 2.23 KB

Rules: Internal Port Scan

Description

This rule detects port scanning activity from one internal IP address to another, possibly indicating an attacker enumerating the network for lateral movement.

Additional Details

Detail Value
Type Threshold
Category Discovery
Apply Risk to Entities srcDevice_ip, srcDevice_hostname, user_username
Signal Name Internal Port Scan
Summary Expression Internal port scan from IP: {{srcDevice_ip}}
Threshold Count 20
Threshold Window 5m
Score/Severity Static: 1
Enabled by Default False
Prototype False
Tags _mitreAttackTactic:TA0043, _mitreAttackTechnique:T1595, _mitreAttackTechnique:T1046, _mitreAttackTechnique:T1595.001

Vendors and Products

Fields Used

Origin Field
Normalized Schema dstDevice_ip_isInternal
Normalized Schema dstPort
Normalized Schema listMatches
Normalized Schema objectType
Normalized Schema srcDevice_hostname
Normalized Schema srcDevice_ip
Normalized Schema srcDevice_ip_isInternal
Normalized Schema user_username