cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

TCP: Full-Connect Port Scan

Jump to solution

Hi All

I am getting alert as described in subject.Is this an attack?How I can take remediation steps against this event.This is medium type alert.

1 Solution

Accepted Solutions
YashT McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 2

Re: TCP: Full-Connect Port Scan

Jump to solution

Hello @User27622125 ,

Network Security Platform attacks are set to collect or capture packet logs, but no packet logs are available.

Solution
Because of the way some attacks are detected, the Network Security Platform Sensor does not collect a corresponding packet log, even if it is enabled to do so.

TCP: Full-Connect Port Scan 0x40009400 Reconnaissance Correlation Attack --- ---

 

You can find this details in :

Network Security Platform attacks for which packet logs cannot be collected
Technical Articles ID: KB56050

When you upgrade your NSM from 7.x to 8.x, some attacks will be enabled even though they are disabled by default in a fresh 8.x installation
Technical Articles ID: KB84133

Network Security Platform attacks that cannot be configured for blocking
Technical Articles ID:   KB92145
Was my reply helpful?
If you find this post useful, Please give it a Kudos! l Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!

Thanks and regards,
Yash T

View solution in original post

1 Reply
YashT McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 2

Re: TCP: Full-Connect Port Scan

Jump to solution

Hello @User27622125 ,

Network Security Platform attacks are set to collect or capture packet logs, but no packet logs are available.

Solution
Because of the way some attacks are detected, the Network Security Platform Sensor does not collect a corresponding packet log, even if it is enabled to do so.

TCP: Full-Connect Port Scan 0x40009400 Reconnaissance Correlation Attack --- ---

 

You can find this details in :

Network Security Platform attacks for which packet logs cannot be collected
Technical Articles ID: KB56050

When you upgrade your NSM from 7.x to 8.x, some attacks will be enabled even though they are disabled by default in a fresh 8.x installation
Technical Articles ID: KB84133

Network Security Platform attacks that cannot be configured for blocking
Technical Articles ID:   KB92145
Was my reply helpful?
If you find this post useful, Please give it a Kudos! l Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!

Thanks and regards,
Yash T

View solution in original post

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community