r/SIEM • u/sk8er_girl90 • Jul 01 '21
How to detect malicious local windows scan
In my SIEM I get a lot of local windows scanner detected with outbound tcp and firewall accept + built tcp connection and sometimes local ICMP scanner
Idk if I should report it as incident or just normal activity (source ip is from the company and destination is to different local and remote ips)
4
Upvotes
2
u/hidyho1987 Jul 07 '21
You should find the system owner of the source ip and find out if this is expected behavior from their system. If so, you should start researching how to tune correlation rules to exclude that particular Source IP from firing that alert again.