Forum Discussion

mchhetry14's avatar
mchhetry14
Copper Contributor
Jul 20, 2020

KQL rule to Detect Scanning Activty

I want assistance in building KQL query to detect scanning activity in my network. For example - if any IP or Host is trying to attempt/scan more than 500 distinct IPs or Ports in short interval of ...

Resources