Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Eve_Z
Participant

How to detect Port Scanning with Harmony Endpoint or Infinity XDR/XPR?

Hello,

Have you ever tried to detect port scanning by using Harmony Endpoint? I thought this would be detected by Infinity XDR/XPR as an incident, but I see not incidents related.

I would like to detect port scanning from the machine with Harmony Endpoint that is performing the scan, for example, with a virtualized Kali Linux, AND/OR from the victim machine that also has Harmony Endpoint.

Any suggestion is appreciated.

Regards.

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

At least for a gateway, this requires using a particular IPS signature and a trigger from SmartEvent to actually block based on the IP.
Not sure how this works on Endpoint, if it does at all.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events