Latest known Scanner Source IP Match
This rule monitors network traffic from internal devices and security logs for communication with a curated list of known malicious or suspicious scanner IP addresses, indicating potential reconnaissance or probing activity by external actors.
Microsoft Sentinel (KQL)

