<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to detect Port Scanning with Harmony Endpoint or Infinity XDR/XPR? in Endpoint</title>
    <link>https://community.checkpoint.com/t5/Endpoint/How-to-detect-Port-Scanning-with-Harmony-Endpoint-or-Infinity/m-p/240896#M10200</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Have you ever tried to detect port scanning by using Harmony Endpoint? I thought this would be detected by Infinity XDR/XPR as an incident, but I see not incidents related.&lt;/P&gt;&lt;P&gt;I would like to detect port scanning from the machine with Harmony Endpoint that is performing the scan, for example, with a virtualized Kali Linux, AND/OR from the victim machine that also has Harmony Endpoint.&lt;/P&gt;&lt;P&gt;Any suggestion is appreciated.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2025 12:53:12 GMT</pubDate>
    <dc:creator>Eve_Z</dc:creator>
    <dc:date>2025-02-11T12:53:12Z</dc:date>
    <item>
      <title>How to detect Port Scanning with Harmony Endpoint or Infinity XDR/XPR?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/How-to-detect-Port-Scanning-with-Harmony-Endpoint-or-Infinity/m-p/240896#M10200</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Have you ever tried to detect port scanning by using Harmony Endpoint? I thought this would be detected by Infinity XDR/XPR as an incident, but I see not incidents related.&lt;/P&gt;&lt;P&gt;I would like to detect port scanning from the machine with Harmony Endpoint that is performing the scan, for example, with a virtualized Kali Linux, AND/OR from the victim machine that also has Harmony Endpoint.&lt;/P&gt;&lt;P&gt;Any suggestion is appreciated.&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 12:53:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/How-to-detect-Port-Scanning-with-Harmony-Endpoint-or-Infinity/m-p/240896#M10200</guid>
      <dc:creator>Eve_Z</dc:creator>
      <dc:date>2025-02-11T12:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to detect Port Scanning with Harmony Endpoint or Infinity XDR/XPR?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/How-to-detect-Port-Scanning-with-Harmony-Endpoint-or-Infinity/m-p/240923#M10201</link>
      <description>&lt;P&gt;At least for a gateway, this requires using a particular IPS signature and a trigger from SmartEvent to actually block based on the IP.&lt;BR /&gt;Not sure how this works on Endpoint, if it does at all.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 15:39:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/How-to-detect-Port-Scanning-with-Harmony-Endpoint-or-Infinity/m-p/240923#M10201</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-02-11T15:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: How to detect Port Scanning with Harmony Endpoint or Infinity XDR/XPR?</title>
      <link>https://community.checkpoint.com/t5/Endpoint/How-to-detect-Port-Scanning-with-Harmony-Endpoint-or-Infinity/m-p/241556#M10237</link>
      <description>&lt;P&gt;I created a custom query for Threat Hunting to detect TCP connections with 0 bytes received, excluding common ports. This should detect when the source tries to open a connection to an uncommon port that is filtered (destination does not respond, so 0 bytes are received), which may indicate port scanning.&lt;/P&gt;&lt;P&gt;This query shows some results when scanning with Nmap from a machine with Harmony Endpoint, but when I scan from a virtualized Kali Linux from the same machine, I don't see the same results. I was expecting to see a VirtualBox process doing the same connections.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Feb 2025 15:30:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Endpoint/How-to-detect-Port-Scanning-with-Harmony-Endpoint-or-Infinity/m-p/241556#M10237</guid>
      <dc:creator>Eve_Z</dc:creator>
      <dc:date>2025-02-18T15:30:13Z</dc:date>
    </item>
  </channel>
</rss>

