Multiple scans in the network (Microsoft Defender for IoT)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This alert leverages Defender for IoT to detect multiple scans on the network indicating new devices, functionality, application misconfiguration, or malicious reconnaissance activity on the network.

Attribute Value
Type Analytic Rule
Solution IoTOTThreatMonitoringwithDefenderforIoT
ID 493916d5-a094-4bfa-bdd1-d983a063ea3d
Severity High
Status Available
Kind Scheduled
Tactics Discovery
Techniques T0842
Required Connectors IoT
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
SecurityAlert ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to IoTOTThreatMonitoringwithDefenderforIoT