title: Network Scans id: fab0ddf0-b8a9-4d70-91ce-a20547209afb description: Detects many failed connection attempts to different ports or hosts author: Thomas Patzke logsource: category: firewall detection: selection: action: denied timeframe: 24h condition: - selection | count(dst_port) by src_ip > 10 - selection | count(dst_ip) by src_ip > 10 fields: - src_ip - dst_ip - dst_port falsepositives: - Inventarization systems - Vulnerability scans - Penetration testing activity level: medium