Techniques › T1595.001 › AN1949
AN1949 Analytic 1949
PRE · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Monitoring the content of network traffic can help detect patterns associated with active scanning activities. This can include identifying repeated connection attempts, unusual scanning behaviors, or probing activity targeting multiple IP addresses across a network. Monitor network data for uncommon data flows. Processes utilizing the network that do not normally have network communication or have never been seen before are suspicious.</p>
- Detects
- T1595.001 Scanning IP Blocks
- Part of
- DET0817 Detection of Scanning IP Blocks
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| Network Traffic | None | DC0085 Network Traffic Content |
| Network Traffic | None | DC0078 Network Traffic Flow |