Lesson 2 of 2 in nmap
What Your Scan Looks Like From There
A port scan is not quiet. Here is the shape it makes in somebody else's log, and why that shape is both easy to spot and useless to alert on.
2 min read
Not yet reviewed
Every scan you run appears in somebody's logs. Knowing what it looks like is what stops you being surprised by a phone call, and it is also how you recognise one aimed at you.
Aug 14 02:11:03 gw kernel: [UFW BLOCK] SRC=198.51.100.44 DPT=21
Aug 14 02:11:03 gw kernel: [UFW BLOCK] SRC=198.51.100.44 DPT=23
Aug 14 02:11:03 gw kernel: [UFW BLOCK] SRC=198.51.100.44 DPT=25
Aug 14 02:11:03 gw kernel: [UFW BLOCK] SRC=198.51.100.44 DPT=110
Aug 14 02:11:04 gw kernel: [UFW BLOCK] SRC=198.51.100.44 DPT=143
# ...and about sixty-five thousand more, from one address, in four seconds
One source, thousands of destination ports, one or two seconds. No human and no legitimate client produces that pattern, which makes a scan one of the easiest things in security to recognise.
Note
It is also one of the least useful things to alert on, and both facts are true at once. Every public address is scanned continuously by automated systems that have never heard of you. An alert on "somebody scanned us" fires all day and teaches people to close the tab.
What is worth noticing instead
Weather
A full port sweep from an address you never see again
Thousands of blocked SYNs to closed ports
The same twenty ports, from a hundred addressesWorth a look
A scan followed, minutes later, by a connection that succeeded
A scan of an internal range, from inside
A scan that only touches ports you actually runThe right column is the same reasoning as the access log in the forensics course: the scan is not the signal, the thing that happened *after* the scan is. Somebody who found something stops scanning.
The third one is the sharpest. A scanner sprays a fixed list of well-known ports at everyone. Somebody probing only the four services you actually run has already done reconnaissance you did not see.
Slowing down does not help as much as people think
Scanners often reach for timing options to stay under a threshold, and against a simple rate-based rule that works. Against a log that anybody reads later, it does not — the pattern is still one source touching ports it has no business touching, just spread out.
Take care
Do not scan hosts you do not own or have written permission to test. In many jurisdictions an unauthorised port scan is at least a civil matter and sometimes a criminal one, and "I was only looking" is not the defence people assume it is.
Which of these is most worth investigating?