1200kmSECURITY RESEARCH

1200KM / lab

T1595 Active Scanning — Bounded Nmap Lab

Reproduce open-port fan-out on loopback, inspect actual application connection records, and evaluate an educational threshold and anomaly example.

Scope and observed result

This lab binds 32 disposable listeners on 127.0.0.1:18080–18111, runs Nmap TCP connect scanning against those listeners, and records actual application-side socket accepts. It does not scan another host, use scripts, download payloads or require administrator access.

Observed: 32 destination ports; 1 matching one-minute detector window(s). Tool: Nmap version 7.94SVN ( https://nmap.org ). Captured result and exact scope.

Limits: loopback/open ports only, not an external perimeter test. Closed and filtered probes are absent from this collector. Packet capture was not run here because capture permission was unavailable. No full-T1595 or production detection validation is claimed.

Run only in your owned lab

Requires Python 3 and a separately installed Nmap. All targets and ports are fixed in the reviewed source; if a listener port is occupied, the run stops and releases its own resources. Use a new output directory each time.

python3 run-application-lab.py --output ./new-scan-evidence

Review/download the loopback lab source · Nmap and your five guides · Nmap TCP connect scanning documentation

/usr/bin/nmap -sT -Pn -n -p 18080-18111 --scan-delay 100ms --max-retries 0 --host-timeout 10s 127.0.0.1

Native telemetry and detector

The collector emits its own 1200km.lab.tcp-accept.v1 records from actual socket accept calls. These are not Zeek or firewall logs. The explicit adapter maps source/destination/time into the educational detector’s input fields. No timestamps are shifted to force a result.

Actual connection records · Nmap output · Capture provenance and SHA-256 hashes · Executable detector and explicit adapter

Within each fixed 60-second window, by source:
connections >= 20 AND (distinct destination ports >= 20 OR distinct destination hosts >= 20)
Exclude explicitly approved scanner sources.
Missing or invalid telemetry is inconclusive, not benign.

The source is importable in Node.js: call normalizeAcceptRecords(records), then scanFeatures(events). A native Zeek conn.log JSON record already has the required input keys; compatibility does not prove packet collection.

Anomaly example and controls

The example scores destination-port fan-out against a synthetic 30-window toy baseline, using median/MAD. It is not a trained production baseline. Baseline and evaluation data are separate; zero dispersion and insufficient samples return explicit non-results.

Unit tests cover a positive fan-out fixture, ordinary repeated connections, an approved scanner, missing/invalid events, low-and-slow scans that this rule misses, short baselines and zero MAD. No production precision/recall is reported.

Validation and blind spots · T1595 anomaly design

Optional packet-capture path

Optional dumpcap + Zeek procedure is a separate unexecuted path requiring approved capture permissions. Do not elevate or change machine permissions automatically. Keep its future packet evidence separate from the observed application records above.

Connected ecosystem references

Connected technique and detection pages

T1595 Active Scanning · Detection workspace · T1046 internal service discovery · Network Traffic Flow collection

Pinned research references. No browser attack runner or production-validated detector is asserted. Imported procedures remain unvalidated; any bounded lab evidence has its own scope. ATT&CK / Atomic provenance · Detection provenance.