ipmi_scan_internal_internal
Explanation
IPMI (Intelligent Platform Management Interface) is a protocol that enables remote management of servers and other network devices without relying on the device's CPU or Operating System. IPMI is known to have several security weaknesses. This NDM is designed to detect IPMI scanning inside the customer's network.
What to Look For
Unauthorized scanning activity launched inside your network may be an indication that your network is compromised. Investigate hosts that are the source of this sort of activity in order to make sure that it is authorized and expected, and the hosts have not been compromised. Authorized scanners should be labeled in Netography Fusion so that scanning events do not trigger for them.
Related MITRE ATT&CK Categories
Updated 20 days ago