The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

IPS reconnaissance event details for port scans

Prev Next

To display detailed information about a group of IPS port scan events listed in the IPS Events page, click the entry's expand icon ( ctrl_ips_add.png ) next to the check box.

The following example shows the drill-down view of a one-to-many port scan event entry.

scap_ips_events_reconnaissance_detail_portscan_rule_ip.png

The following table describes the port scan-specific fields in the drill-down view of an IPS port scan event entry.

Field

Description

IP Protocol

TCP or UDP

Victim Port

Port number last attacked on the most recent victim.

Victim IP

IP address of the most recent victim.

Recon Events - Port Scan

Total Connection Count per Event

Number of TCP or UDP connections monitored for all events in the entry.

Victim IPs

IP addresses of the most recent victims (up to 5 addresses).

Attacker IPs

IP addresses of the most recent attackers (up to 5 addresses).

Victim IP Count

Number of victims identified.

NOTE: This value might be an estimate.

Victim IP Range

Lowest and highest victim IP addresses.

Victim Port Count

Number of victim ports identified.

NOTE: This value might be an estimate.

Attacker IP Count

Number of attackers identified.

NOTE: This value might be an estimate.

Attacker IP Range

Lowest and highest attacker IP addresses.

Note

For most IPS port scan events, certain statistics are estimated values rather than exact counts. The following values are provided as reference information only:

  • Victim IP Count

  • Victim Port Count

  • Attacker IP Count

Analysis of port scan activity is a resource-intensive process. When it is necessary to conserve resources, the analysis process does not record all IP addresses or port numbers involved in the port scan activity. In this case, the process must estimate the count of IP addresses or port numbers. To estimate the count, the process compares the current IP address or port count with the most recent IP addresses or port counts in cache memory.