Managed Sentinel – Alert 145

Alert IDMS-A145
Alert NameHigh count of connections by client IP on many ports
DescriptionIdentifies when 30 or more ports are used for a given client IP in 10 minutes occurring on the IIS server. This could be indicative of attempted port scanning or exploit attempt at internet facing web applications. This could also simply indicate a misconfigured service or device.
Severity LevelMedium
Threat Indicator
MITRE ATT&CK TacticsDiscovery
Log sourcesW3CIISLog
False Positives