cleo_scan_internal_external
Explanation
This NDM is designed to detect scanning for Cleo Managed File Transfer that is exiting the customer's network. Cleo offers a family of file transfer products, including Cleo Harmony, Cleo VLTrader, and Cleo LexiCom, that have been subject to vulnerability disclosures in the past.
What to Look For
Scans launched from your network may be an indication that your network is compromised. Investigate hosts that are the source of this sort of activity in order to make sure that it is authorized and expected, and the hosts have not been compromised. This event could false positive in a situation where Netography has not been configured with the appropriate internal network IP address ranges.
Related MITRE ATT&CK Categories
Discovery: Network Service Discovery, Technique T1046 - Enterprise
Reconnaissance: Active Scanning, Technique T1595 - Enterprise
Updated 13 days ago