Port Knocking Detected Followed by Sensitive Service Access
This rule detects a classic port knocking sequence followed by a connection to sensitive services (SSH, Telnet, RDP, VNC, WinRM). The rule identifies devices performing rapid connections to multiple different ports within a short window, which is indicative of a port knocking attempt used to trigger service exposure, followed by an immediate attempt to connect to that exposed service.
Microsoft Sentinel (KQL)

