NGFW Internal Scan

This playbook investigates a scan where the source is an internal IP address. An attacker might initiate an internal scan for discovery, lateral movement and more. **Attacker's Goals:** An attacker can leverage a scan for open ports and vulnerable systems on remote endpoints in an attempt to identify the endpoint operating system, firewall configuration, and exploitable services. **Investigative Actions:** * Endpoint Investigation Plan playbook **Response Actions** The playbook's response actions are based on the Endpoint Investigation Plan playbook results. In that phase, the playbook will execute: * Auto endpoint isolation * Manual block indicators * Manual file quarantine

Pack
Core
Tasks
16

Inputs

Commands used