Loading interactive filters…
1200KM / detection
T1595 Active Scanning — Detection Rules
Detection workspace for T1595 Active Scanning: 3 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.
Source-backed rule directory
Atlas deterministic concepts
T1595 Active Scanning
COUNT(denied_or_failed_connections BY source_ip, 5m) >= threshold AND DISTINCT_COUNT(destination_port OR destination_host) >= threshold -> ALERT
Anomaly models
Repeated probing of public services — T1595 Active Scanning
Comparison unit: source address or source network.
Expected behavior: ordinary clients contact a small set of exposed services.
Deviation: unusually high destination-port or destination-host fan-out within a short interval.
ATT&CK analytic guidance
Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.
Monitor and analyze traffic patterns and packet inspection associated to protocol(s) that do not follow the expected protocol standards and traffic flows (e.g extraneous packets that do not belong to established flows, gratuitous or anomalous traffic patterns, anomalous syntax, or structure). Consider correlation with process monitoring and command line to detect anomalous processes execution and command line arguments associated to traffic patterns (e.g. monitor anomalies in use of files that do not normally initiate connections for respective protocol(s)).
Connected ecosystem references
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.