Detection & alerting · 5 min read

Configure port-scan and recon detection

Sequential or unusual connection attempts across a range of ports and hosts get surfaced as a detection instead of getting lost in normal traffic noise.

What you'll need

  • Flow data (NetFlow, IPFIX or sFlow) reporting from at least one sensor
1

Understand the default thresholds

Out of the box, Linivo flags a source host that touches more than 20 distinct destination ports on a single target, or more than 15 hosts on the same port, within a 60-second window.

2

Adjust for your environment

Networks with legitimate broad scanning, like a vulnerability-management platform, should either be excluded by source IP or have their threshold raised under Detections > Port scan > Thresholds.

3

Route detections separately

Route port-scan detections to a security-focused Slack channel or PagerDuty service distinct from your general alerting, since they usually need a different responder than a failing interface.