> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/port-sweep.md).

# Port Sweep

### Synopsis

| Field                | Value                                                                                                                                |
| -------------------- | ------------------------------------------------------------------------------------------------------------------------------------ |
| Activation Period    | 14 Days                                                                                                                              |
| Training Period      | 30 Days                                                                                                                              |
| Test Period          | 1 Hour                                                                                                                               |
| Deduplication Period | 1 Day                                                                                                                                |
| Required Data        | <p>Requires one of the following data sources:<br>Palo Alto Networks Firewall traffic Logs OR XDR Agent OR Third-Party Firewalls</p> |
| ATT\&CK Tactic       | Discovery (TA0007)                                                                                                                   |
| ATT\&CK Technique    | Network Service Discovery (T1046)                                                                                                    |
| Severity             | Informational                                                                                                                        |

### Description

The endpoint connected, or attempted to connect, to multiple hosts using privileged ports that serve a well-defined function. Attackers perform port sweep for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port sweeps using data arriving solely from Cortex agents is incomplete.

### Attacker's Goals

An attacker is determining which ports are open or closed on remote endpoints in an attempt to identify the endpoint operating system, firewall configuration, and exploitable services.

### Investigative actions

* Ensure that the source of the port sweep is not a new server in the network. New domain controllers or servers hosting services such as SNMP can cause false positives.
* Check for new known vulnerabilities in the ports scanned, this method is often used to target known vulnerabilities.

### Variations

<details>

<summary>Port Sweep to multiple subnets</summary>

**Synopsis**

| Field             | Value                             |
| ----------------- | --------------------------------- |
| ATT\&CK Tactic    | Discovery (TA0007)                |
| ATT\&CK Technique | Network Service Discovery (T1046) |
| Severity          | Low                               |

**Description**

The endpoint connected, or attempted to connect, to multiple hosts using privileged ports that serve a well-defined function. Attackers perform port sweep for reconnaissance purposes, to find computers or servers that accept connections on these ports, and to find vulnerable services that can be exploited. Coverage for port sweeps using data arriving solely from Cortex agents is incomplete.

**Attacker's Goals**

An attacker is determining which ports are open or closed on remote endpoints in an attempt to identify the endpoint operating system, firewall configuration, and exploitable services.

**Investigative actions**

* Ensure that the source of the port sweep is not a new server in the network. New domain controllers or servers hosting services such as SNMP can cause false positives.
* Check for new known vulnerabilities in the ports scanned, this method is often used to target known vulnerabilities.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/port-sweep.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
