Nessus Scanner Detected Targeting Domain Controller

Detects high-volume, multi-port connections from a single source to a domain controller, which is indicative of vulnerability scanning activity such as Nessus. The rule monitors for a large volume of connection attempts across multiple sensitive ports (e.g., 88, 135, 389, 445, 464, 636, 3268, 3269) within a short 5-minute window.