elastic
low
kql
Potential Network Scan Detected
This rule identifies a potential port scan from an internal IP address. A port scan is a method utilized by attackers to
systematically scan a target system for open ports, allowing them to identify available services and potential
vulnerabilities. By mapping out the open ports, attackers can gather critical information to plan and execute targeted
attacks, gaining unauthorized access, compromising security, and potentially leading to data breaches, unauthorized
control, or further exploitation