3000_scan_internal_internal

Explanation

This NDM is designed to detect scanning for servers listening on port 3000 inside the customer's network. Numerous technologies have used port 3000. One noteworthy example is Grafana, an open source data visualization platform that has been subject to a number of critical vulnerability disclosures.

What to Look For

Unauthorized scanning activity launched inside your network may be an indication that your network is compromised. Investigate hosts that are the source of this sort of activity in order to make sure that it is authorized and expected, and the hosts have not been compromised. Authorized scanners should be labeled in Netography Fusion so that scanning events do not trigger for them.

Related MITRE ATT&CK Categories

Discovery: Network Service Discovery, Technique T1046 - Enterprise