title: Network Scans id: fab0ddf0-b8a9-4d70-91ce-a20547209afb status: experimental description: Detects many failed connection attempts to different ports or hosts author: Thomas Patzke date: 2017/02/19 modified: 2020/08/27 logsource: category: firewall detection: selection: action: denied timeframe: 24h condition: - selection | count(dst_port) by src_ip > 10 - selection | count(dst_ip) by src_ip > 10 fields: - src_ip - dst_ip - dst_port falsepositives: - Inventarization systems - Vulnerability scans - Penetration testing activity level: medium tags: - attack.discovery - attack.t1046