The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

Port scan alert

Prev Next

All alerts that has iv_alert.alertType = 4 are port scan alerts. Its iv_alert_data.typeSpecific data has the following format:

First byte contains number of port information to follow. If there are five ports involved in port scan then first byte of typeSpecificData will contain value 5. Each subsequent 2 bytes will contain the actual port number values.

Total length of typeSpecificData will be 1 + ( 5*2) = 11 bytes.

The source and destination VLAN ID follow with each being 4 bytes. These fields are applicable only for NTBA alerts.

The details of the alert are as follows:

Number of bytes

Value

1

Version information

4 (IPv4) or 16 (Ipv6)

IP address

1

Total number of ports

2

Port information

Variable length

Packet logs

Port scan
Port scan