Active Scanning Reconnaissance Analysis: T1595 – Port Scan & Service Enumeration
SIEM Alert Details Alert ID: SIEM-RECON-PORTSCAN-7842Alert Time: 2024-02-01 08:22:15 ESTSeverity: MEDIUM (65/100)Source: Splunk Enterprise Security Correlation RuleRule: “Internal Port Scan Detected – Horizontal Sweep”MITRE ATT&CK: T1595 – Active Scanning (Sub-technique T1595.001: Scanning IP Blocks) Alert Details: Correlated Events: Threat Intelligence Context: SOC Investigation Process Phase 1: Alert Validation & Initial Triage (08:22-08:40 EST) Tools: Splunk … Read more