Detect port scanning activity in firewall and network logs. Identify reconnaissance attempts, service enumeration, and pre-attack probing targeting your infrastructure.
-- Firewall log showing SYN scan pattern: Mar 8 14:22:01 fw01 kernel: DROP IN=eth0 SRC=198.51.100.88 DST=10.0.1.50 PROTO=TCP SPT=45231 DPT=22 SYN Mar 8 14:22:01 fw01 kernel: DROP IN=eth0 SRC=198.51.100.88 DST=10.0.1.50 PROTO=TCP SPT=45232 DPT=23 SYN Mar 8 14:22:01 fw01 kernel: DROP IN=eth0 SRC=198.51.100.88 DST=10.0.1.50 PROTO=TCP SPT=45233 DPT=25 SYN Mar 8 14:22:02 fw01 kernel: DROP IN=eth0 SRC=198.51.100.88 DST=10.0.1.50 PROTO=TCP SPT=45234 DPT=80 SYN Mar 8 14:22:02 fw01 kernel: DROP IN=eth0 SRC=198.51.100.88 DST=10.0.1.50 PROTO=TCP SPT=45235 DPT=443 SYN Mar 8 14:22:02 fw01 kernel: DROP IN=eth0 SRC=198.51.100.88 DST=10.0.1.50 PROTO=TCP SPT=45236 DPT=3389 SYN