Answer the question
In order to leave comments, you need to log in
Is there a way to configure sysmon logging to show nmap/port scanner activity?
The ability to configure sysmon logging (config settings) to display the activity of nmap / port scanners is very interesting. Is it possible at all or just snort?
As I understand it, sysmon will only log suspicious outgoing connections if the config is configured accordingly.
Py. sy. the request strongly not to kick sensible information anywhere did not find.
Answer the question
In order to leave comments, you need to log in
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question