DETECTION OVERVIEW
Risk Factors
Connections to websites and servers from IP addresses associated with known malicious servers might indicate impending attempts to discover vulnerabilities. Suspicious IP addresses can be identified from threat intelligence, which is a collection of information curated by the security community.
Kill Chain
Risk Score
60
N/A
Block inbound and outbound traffic from suspicious IP addresses at the network perimeter
Quarantine the device while checking for indicators of compromise, such as the presence of malware
Implement network segmentation and the principle of least privilege on accounts to minimize the damage caused by a compromised device