I used the DeviceNetworkEvents table in Microsoft Defender XDR to alert on anomalous SMB enumeration: one unusual source IP probing SMB ports on multiple different devices in a short period. The rule considers the spread of activity across devices and time, connecting individual network events to a reconnaissance pattern.
Viewed
UK Water Utility
Detect one source probing SMB across multiple devices
From Red Team findings to SQL and SMB detections
Return to the full story ←