Vulnerability scanner triggers lateral movement signature
A-105400:00time on this alert, target 20 minutes
Back to queueAlert details
- Source
- IDS
- Detection rule
- IDS-LATERAL-SMB-009
- Affected user
- svc-backup
- Affected host
- SRV-BACKUP-01
- Source IP
- 10.20.9.30
- First seen
- 2026-07-24T15:33:00Z
Why this fired, in plain English
One computer contacted the file-sharing port on many other computers.
Suggested playbook
Lateral movement
- 1. Check whether the source is a known scanner in the asset database.
- 2. Measure the spread: how many hosts, over how long, on which ports?
- 3. Look for file writes to remote admin shares.
- 4. Check logon types: 3 (network), 9 (runas), 10 (RDP) tell you how credentials were used.
Raw log evidence
Exactly what the tools recorded — 3 events.
Guided hint: this line matters
ts=2026-07-24T15:30:00Z src="ids" event=port_scan src_ip=10.20.9.30 dest_subnet=10.20.0.0/16 dest_port=445,139,3389,22 unique_hosts=1402 duration_sec=1800
Scanning every subnet on many ports over 30 minutes is the signature of an authorized vulnerability scan, not a stealthy attacker.
Guided hint: this line matters
ts=2026-07-24T15:30:00Z src="asset_db" event=lookup ip=10.20.9.30 hostname="SCAN-VULN-01" tag="authorized_scanner" owner="security_engineering"
The asset database identifies this IP as the company's own vulnerability scanner.
Guided hint: this line matters
ts=2026-07-24T15:29:40Z src="itsm" event=schedule task="Weekly authenticated vuln scan" window="2026-07-24T15:30Z/2026-07-24T18:00Z" owner="security_engineering"
Related events
The order things happened in.
15:29Z
Scheduled scan window opens
15:30Z
Scanner sweeps 1,402 hosts
Enrichment lookups
Mock lookups. Run each one yourself — a real analyst never guesses what a lookup would have said. There is no "run everything" button on purpose.
Not checked yet.
Not checked yet.
techniques
Your verdict
Keyboard shortcuts 1–4, or click. You can always change your mind afterwards.