{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/nmap/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AWS CloudWatch","Cisco Secure Firewall Threat Defense"],"_cs_severities":["medium"],"_cs_tags":["reconnaissance","network-discovery","internal-scanning","nmap"],"_cs_type":"advisory","_cs_vendors":["Amazon","Cisco"],"content_html":"\u003cp\u003eThis brief outlines a behavioral detection analytic designed to identify internal horizontal port scanning, a common precursor to lateral movement and network exploitation. The detection triggers when an internal host attempts to initiate connections to 250 or more unique destination IP addresses within a one-hour window, specifically targeting ports frequently probed by the NMAP tool (e.g., 21, 22, 23, 25, 53, 80, 443, 3389, 445, 3306).\u003c/p\u003e\n\u003cp\u003eThis activity is characteristic of network discovery and reconnaissance performed by threat actors or automated worms to map internal network segments, identify accessible services, and locate potential targets for further compromise. Because this detection monitors network telemetry from infrastructure such as VPC flow logs and firewall connection events, it provides visibility into malicious movement that might otherwise bypass endpoint-based security controls. Defenders should use this analytic to flag unauthorized scanning within the internal network segment.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful internal reconnaissance allows attackers to map internal topology, identify vulnerable services (e.g., SMB/RDP), and stage lateral movement. Unauthorized scanning can lead to data exfiltration, service disruption, and eventual compromise of business-critical assets. Detecting this activity early is essential to interrupting the attack lifecycle before an actor gains persistence or access to sensitive data stores.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to your SIEM/Detection platform to monitor network traffic for high-volume, horizontal port scanning behavior.\u003c/li\u003e\n\u003cli\u003eIntegrate telemetry from network infrastructure (Cisco Secure Firewall, AWS VPC Flow Logs) into the organization's SIEM to populate the Network_Traffic data model required for this detection.\u003c/li\u003e\n\u003cli\u003eInvestigate any triggered alerts immediately to determine if the source IP is a legitimate administrative scanner, a misconfigured automation, or a compromised asset performing unauthorized reconnaissance.\u003c/li\u003e\n\u003cli\u003eReview network access control lists (ACLs) and firewall policies to restrict unnecessary inter-zone communication, especially for sensitive internal segments.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-21T19:13:15Z","date_published":"2026-09-21T19:13:15Z","id":"https://feed.craftedsignal.io/briefs/2026-09-internal-horizontal-port-scan/","summary":"Detection logic identifying internal hosts performing broad network reconnaissance by scanning 250+ unique IP addresses across NMAP's top 20 common ports.","title":"Detection of Internal Horizontal Port Scanning Activity","url":"https://feed.craftedsignal.io/briefs/2026-09-internal-horizontal-port-scan/"}],"language":"en","title":"CraftedSignal Threat Feed - Nmap","version":"https://jsonfeed.org/version/1.1"}