The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

About IPS detection of reconnaissance activity

Prev Next

Network reconnaissance is the unauthorized discovery of the victim's network topology and the active services within the network. Intruders use the information to identify vulnerabilities to be exploited in future attacks. Typically, intruders run ping sweeps across the subnets in the target network to find live IP addresses. Next, port scans of the host IP addresses discover open ports. Intruders query the ports to determine the operating systems and applications running on the target hosts.

To detect reconnaissance activity, a platform engine detects repeated connections and queries to or from the same host. The platform engine tracks and analyzes the sources, destinations, and amount of each suspicious traffic flow. Through analysis of the suspicious traffic and hosts, the engine can separate reconnaissance attacks from normal network traffic. When a reconnaissance attack is detected, the system triggers an IPS ping sweep event or an IPS port scan event

When IPS detection of reconnaissance activity is enabled, the platform detects reconnaissance activity that targets ports, hosts, and networks.

Ping sweeps

When the IPS-enabled engine identifies certain ICMP echo requests and replies, it tracks the source IP addresses (the attackers) and destination IP addresses (the victims). The platform triggers an IPS ping sweep event when the number of ICMP messages in a session exceeds a configurable threshold within a rolling 60‑second window. Ping sweep detection is supported on IPv4 and IPv6 networks.

Port scans

When the IPS-enabled engine identifies certain TCP or UDP connection flows, it tracks the source IP address (the attacker) and its last five destination IP addresses (victims). The engine triggers an IPS port scan event when the number of TCP or UDP messages exceeds a configurable threshold within a rolling 60‑second window. Port scan detection is supported on IPv4 and IPv6 networks.

The rules detect the following types of port scans:

  • TCP SYN

  • TCP SYN+ACK

  • TCP Connect

  • TCP NULL

  • TCP FIN

  • TCP XMAS

  • UDP

Frequent connections to a service port on a single victim IP address do not trigger IPS reconnaissance events. Attackers typically do not scan the same port on the same IP address many times. Automatic suppression of events for this type of activity prevents false positive from triggering on valid network traffic, such as DNS packets and NETBIOS Name Service packets.

Note

Reconnaissance detection consumes additional system resources. Depending on your traffic load and IPS policies, operating the platform in reconnaissance detection mode can slow IPS processing. For that reason, IPS detection of reconnaissance activity is disabled by default.

IPS reconnaissance events do not trigger FireEye event notifications and cannot be acknowledged.