Port Sweep
The endpoint connected, or attempted to connect, to multiple hosts using privileged ports that serve a well-defined function. Attackers perform port sweep for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port sweeps using data arriving solely from Cortex agents is incomplete.
- Module:
- Platform Analytics
- Data source:
- Palo Alto Networks Firewall traffic Logs, XDR Agent, Third-Party Firewalls
An attacker is determining which ports are open or closed on remote endpoints in an attempt to identify the endpoint operating system, firewall configuration, and exploitable services.
Ensure that the source of the port sweep is not a new server in the network. New domain controllers or servers hosting services such as SNMP can cause false positives. Check for new known vulnerabilities in the ports scanned, this method is often used to target known vulnerabilities.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
- Port Sweep to multiple subnets Low (parent: Informational)