Welcome, Guest [Login]
Traffic Sentinel
Filter:

Port Scanning Activity
Section
Description
incl (optional)
Exclude Protocol (optional)
Attacker
Victim
Interval (?)
Truncate
Severity
Notification Cache
Show
Threshold (optional)
Where (optional) (?)

Usage: Specify Protocols to Ignore or Include. Set a Threshold on the number of hosts scanned and a Severity to generate notifications when a scanning host is detected. Set the Notification Cache interval to suppress duplicate events, only generating an event when a new host starts scanning, or resumes having been silent for the Notification Cache interval. To continuously monitor for scanning activity, include this section in a report and schedule the report to run at the same frequency as the specified Interval.