DragonForce Ransomware TCP/445 /24 Subnet Discovery Scan
Detects rapid TCP connection attempts to port 445 (SMB) from a single source IP address, indicative of network scanning or reconnaissance activities typically used by the DragonForce ransomware or similar automated threats for lateral movement.
Suricata

