# How to detect network scan using EQL

**URL:** <https://discuss.elastic.co/t/how-to-detect-network-scan-using-eql/266466>\
**Category:** Elasticsearch\
**Created:** [March 7, 2021, 8:58am UTC](https://discuss.elastic.co/t/how-to-detect-network-scan-using-eql/266466 "2021-03-07T08:58:42Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![msszafar](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@msszafar](https://discuss.elastic.co/u/msszafar)\
**Post date:** [March 7, 2021, 8:58am UTC](https://discuss.elastic.co/t/how-to-detect-network-scan-using-eql/266466/1 "2021-03-07T08:58:42Z")

</div>

Hi All,

Can anyone please help me setting up a simple correlation rule using EQL that detect if same source.ip attempts more than 50 destination.ip within 15 minutes.

I'm unable to write EQL.

I've fortigate logs, my correlation rule is like

```
sequence by source.ip maxspan=15m
[network where event.action == "deny"]
[network where true]

```

I know here `by source.ip` means same source.ip. `network` is value present in the event.category field. `network where true` is just because there must have two sequence patterns in brackets . 2nd condition is like event.category **network** should exists.

**How EQL will detect more than 50 destination.ip?**

---

<div class="post-metadata">

**Author:** ![rw-access](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rw-access/32/47998_2.png) [@rw-access](https://discuss.elastic.co/u/rw-access)\
**Post date:** [March 10, 2021, 6:19am UTC](https://discuss.elastic.co/t/how-to-detect-network-scan-using-eql/266466/2 "2021-03-10T06:19:42Z")

</div>

Hi @msszafar,

It looks like you have the core idea right, that `by` and `maxspan=15m` are two ways to add your conditions to the query. Currently, there's no shorthand to say "at least 50 events" within the sequence. The only way to do that today with EQL:

```auto
sequence by source.ip with maxspan=15m
  [network where event.action == "deny"]
  [network where event.action == "deny"]
  [network where event.action == "deny"]
  [network where event.action == "deny"]
  [network where event.action == "deny"]
  // 45 more times

```

There are some discussions to make this syntax more expressive and succinct. But I'm not sure what/when that will be.

Alternatively, you can play around with a threshold rule which aggregates of a lot of things that look the same. It doesn't have sliding windows like EQL, but it will most likely be more performant.

Hope this helps!  
Ross

---

<div class="post-metadata">

**Author:** ![msszafar](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@msszafar](https://discuss.elastic.co/u/msszafar)\
**Post date:** [March 10, 2021, 6:23am UTC](https://discuss.elastic.co/t/how-to-detect-network-scan-using-eql/266466/3 "2021-03-10T06:23:09Z")

</div>

> [@msszafar](#):
>
> How EQL will detect more than 50 destination.ip?

Sir, As per my usecase, if 1 source IP attempts more than 50 unique destination IPs within 15 minutes then it should trigger an alert.

How should I write EQL that detect if more than 50 unique destinations were accessed from same source IP within 15 minutes.

---

<div class="post-metadata">

**Author:** ![rw-access](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rw-access/32/47998_2.png) [@rw-access](https://discuss.elastic.co/u/rw-access)\
**Post date:** [March 10, 2021, 7:10am UTC](https://discuss.elastic.co/t/how-to-detect-network-scan-using-eql/266466/4 "2021-03-10T07:10:46Z")

</div>

Oh, more than 50 _unique_ destinations. I'm sorry I didn't understand that part.

There's no way to do that in EQL today. I understand that there is a [feature under active development](https://github.com/elastic/kibana/pull/90826) for threshold rules that should be able to satisfy these conditions:

- same source IP
- within a 15m bucket (not sliding window, but you can emulate on with from/to parameters combined with the scheduling interval)
- more than 50 _unique_ destination addresses.

---

<div class="post-metadata">

**Author:** ![msszafar](https://avatars.discourse-cdn.com/v4/letter/m/ed655f/32.png) [@msszafar](https://discuss.elastic.co/u/msszafar)\
**Post date:** [March 10, 2021, 6:34pm UTC](https://discuss.elastic.co/t/how-to-detect-network-scan-using-eql/266466/5 "2021-03-10T18:34:00Z")

</div>

Thank you very much

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 7, 2021, 6:34pm UTC](https://discuss.elastic.co/t/how-to-detect-network-scan-using-eql/266466/6 "2021-04-07T18:34:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
