Potential Vulnerability Scanner Activity
This rule detects potential vulnerability scanning activity by identifying devices making multiple successful network connections to specific ports commonly used by vulnerability scanners (8834, 8889, 1241). A device is flagged if it makes 3 or more such connections within a one-hour window.
Microsoft Sentinel (KQL)

