SOP-33: Network Scan & Port Sweep Detection

Detection and response procedures for internal horizontal scanning, SMB/RDP sweeps, and external vertical port scans. Covers ransomware precursor scanning patterns (WannaCry/NotPetya/Conti), single-source multi-destination detection, and Azure Firewall deny log analysis.

2026-08-15T09:48:31.749Z
Rudra Verma, Senior Security Architect & Researcher