DragonForce-style sequential SMB/445 subnet scan preceding share encryption
Detects anomalous sequential SMB scanning patterns across a /24 subnet and subsequent SMB share enumeration attempts (NetShareEnum) from a single host, consistent with reconnaissance activities associated with the DragonForce threat actor group.
Suricata

