Potential Vulnerability Scanning Activity

This rule detects potential vulnerability scanning activity by identifying multiple network connection attempts to common vulnerable ports (135, 139, 445) where the remote URL contains keywords like 'vuln' or 'scan'. It aggregates these activities by device and time, flagging devices with 5 or more such connections within an hour.