Qualys Scanner Detected Targeting Domain Controller

Detects anomalous network scanning behavior from a Qualys scanner towards Domain Controller ports. The rule monitors CommonSecurityLog and NetworkSessions for high volumes of connection attempts (more than 50 within one hour) targeting critical Active Directory ports (88, 135, 389, 445, 636, 3268, 3269). This activity may indicate a scanner configuration error, a compromised scanner, or an adversary attempting to map the environment while masquerading as a security tool.