# connscan\_internal\_internal

**Explanation**

The connscan\_internal\_internal NDM detects connection scanning attempts inside the customer's network. It does this by monitoring for a high rate of aborted successful TCP connections, which may indicate an attacker attempting to discover available services or potential vulnerabilities on network devices. The NDM triggers when it detects a threshold of connections to different services within a certain time period.

**What to Look For**

If the connscan\_internal\_internal NDM is triggered, network administrators should examine the source and destination IP addresses, as well as the ports and protocols involved in the connection attempts. They should also look for any patterns or trends over time, such as a sudden increase in connection attempts from a particular IP address. Endpoint agents should be checked for any sign of malicious activity or malware. Remediation should involve blocking the offending IP addresses and investigating any vulnerabilities or misconfigurations that may have allowed the scanning to occur.

**Related MITRE ATT\&CK Categories**

[Discovery: Network Service Discovery, Technique T1046 - Enterprise](https://attack.mitre.org/techniques/T1046)


---

# Agent Instructions: Querying This Documentation

If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter:

```
GET https://docs.fusion.vectra.ai/detection-models/library/reconnaissance/connscan_internal_internal.md?ask=<question>
```

The question should be specific, self-contained, and written in natural language.
The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
