> For the complete documentation index, see [llms.txt](https://docs.fusion.vectra.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.fusion.vectra.ai/detection-models/library/reconnaissance/connscan_internal_internal.md).

# connscan\_internal\_internal

**Explanation**

The connscan\_internal\_internal NDM detects connection scanning attempts inside the customer's network. It does this by monitoring for a high rate of aborted successful TCP connections, which may indicate an attacker attempting to discover available services or potential vulnerabilities on network devices. The NDM triggers when it detects a threshold of connections to different services within a certain time period.

**What to Look For**

If the connscan\_internal\_internal NDM is triggered, network administrators should examine the source and destination IP addresses, as well as the ports and protocols involved in the connection attempts. They should also look for any patterns or trends over time, such as a sudden increase in connection attempts from a particular IP address. Endpoint agents should be checked for any sign of malicious activity or malware. Remediation should involve blocking the offending IP addresses and investigating any vulnerabilities or misconfigurations that may have allowed the scanning to occur.

**Related MITRE ATT\&CK Categories**

[Discovery: Network Service Discovery, Technique T1046 - Enterprise](https://attack.mitre.org/techniques/T1046)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.fusion.vectra.ai/detection-models/library/reconnaissance/connscan_internal_internal.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
