• Platformchevron right
  • Solutionschevron right
  • Modern NDRchevron right
  • Resourceschevron right
  • Companychevron right

DETECTION OVERVIEW

Inbound Connection from a Suspicious IP Address

Risk Factors

Connections to websites and servers from IP addresses associated with known malicious servers might indicate impending attempts to discover vulnerabilities. Suspicious IP addresses can be identified from threat intelligence, which is a collection of information curated by the security community.

Kill Chain

Caution

Risk Score

60

Detection diagram
Next in Caution: Inbound Connection from a Tor Node

Attack Background

N/A

Mitigation Options

Block inbound and outbound traffic from suspicious IP addresses at the network perimeter
Quarantine the device while checking for indicators of compromise, such as the presence of malware
Implement network segmentation and the principle of least privilege on accounts to minimize the damage caused by a compromised device

What else can RevealX do for you?