Monitor for new processes engaging in scanning activity or connecting to multiple systems by correlating process creation network data.
Monitor for hosts enumerating network connected resources using non-ICS enterprise protocols.
| Data Component | Name | Channel |
|---|---|---|
| Network Traffic Flow (DC0078) | Network Traffic | None |
| Network Traffic Content (DC0085) | Traffic | None |
| Process Creation (DC0032) | Process | None |
| Network Connection Creation (DC0082) | Network | None |