Detection of Scanning IP Blocks

Technique Detected:  Scanning IP Blocks | T1595.001

ID: DET0817
Domains: Enterprise
Analytics: AN1949
Version: 1.0
Created: 21 October 2025
Last Modified: 21 October 2025

Analytics

AN1949

Monitoring the content of network traffic can help detect patterns associated with active scanning activities. This can include identifying repeated connection attempts, unusual scanning behaviors, or probing activity targeting multiple IP addresses across a network.
Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.

Log Sources
Data Component Name Channel
Network Traffic Content (DC0085) Network Traffic None
Network Traffic Flow (DC0078) Network Traffic None