S
S
slavaNBA2020-05-20 00:10:43
System administration
slavaNBA, 2020-05-20 00:10:43

Is there a way to configure sysmon logging to show nmap/port scanner activity?

The ability to configure sysmon logging (config settings) to display the activity of nmap / port scanners is very interesting. Is it possible at all or just snort?

As I understand it, sysmon will only log suspicious outgoing connections if the config is configured accordingly.

Py. sy. the request strongly not to kick sensible information anywhere did not find.

Answer the question

In order to leave comments, you need to log in

1 answer(s)
X
xmoonlight, 2020-05-20
@xmoonlight

Here

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question