<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to find network scanners via stealthwatch in Security Analytics</title>
    <link>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5271972#M1165</link>
    <description>&lt;P&gt;Is the IP for your PC included in an Inside Host Group?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Mar 2025 10:07:03 GMT</pubDate>
    <dc:creator>David Salter</dc:creator>
    <dc:date>2025-03-17T10:07:03Z</dc:date>
    <item>
      <title>How to find network scanners via stealthwatch</title>
      <link>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5269962#M1164</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hello, I &lt;/SPAN&gt;&lt;SPAN class=""&gt;try&lt;/SPAN&gt; &lt;SPAN class=""&gt;to&lt;/SPAN&gt;&lt;SPAN&gt; use option &lt;/SPAN&gt;&lt;SPAN class=""&gt;from&lt;/SPAN&gt;&lt;SPAN&gt; stealthwatch &lt;/SPAN&gt;&lt;SPAN class=""&gt;to&lt;/SPAN&gt;&lt;SPAN&gt; find network scanners. I started ping scan &lt;/SPAN&gt;&lt;SPAN class=""&gt;from&lt;/SPAN&gt; &lt;SPAN class=""&gt;my&lt;/SPAN&gt;&lt;SPAN&gt; PC. After a &lt;/SPAN&gt;&lt;SPAN class=""&gt;while&lt;/SPAN&gt;&lt;SPAN&gt; I saw &lt;/SPAN&gt;&lt;SPAN class=""&gt;that&lt;/SPAN&gt;&lt;SPAN&gt; I have&amp;nbsp;Top Security Event &lt;/SPAN&gt;&lt;SPAN class=""&gt;for&lt;/SPAN&gt; &lt;SPAN class=""&gt;my&lt;/SPAN&gt;&lt;SPAN&gt; host&amp;nbsp; Ping_Scan &lt;/SPAN&gt;&lt;SPAN class=""&gt;with&lt;/SPAN&gt;&lt;SPAN&gt; CI =&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;590&lt;/SPAN&gt;&lt;SPAN&gt;,&lt;/SPAN&gt;&lt;SPAN class=""&gt;400&lt;/SPAN&gt;&lt;SPAN&gt;, &lt;/SPAN&gt;&lt;SPAN class=""&gt;after&lt;/SPAN&gt; &lt;SPAN class=""&gt;it&lt;/SPAN&gt;&lt;SPAN&gt; I went &lt;/SPAN&gt;&lt;SPAN class=""&gt;to&lt;/SPAN&gt;&lt;SPAN&gt; Report -&amp;nbsp;Visibility Assessment -&amp;nbsp;Internal Network Scanners &lt;/SPAN&gt;&lt;SPAN class=""&gt;and&lt;/SPAN&gt;&lt;SPAN&gt; found out &lt;/SPAN&gt;&lt;SPAN class=""&gt;that&lt;/SPAN&gt;&lt;SPAN&gt; there wasn't &lt;/SPAN&gt;&lt;SPAN class=""&gt;my&lt;/SPAN&gt;&lt;SPAN&gt; host which did ping scan&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2025 13:05:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5269962#M1164</guid>
      <dc:creator>dijix1990</dc:creator>
      <dc:date>2025-03-11T13:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to find network scanners via stealthwatch</title>
      <link>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5271972#M1165</link>
      <description>&lt;P&gt;Is the IP for your PC included in an Inside Host Group?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 10:07:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5271972#M1165</guid>
      <dc:creator>David Salter</dc:creator>
      <dc:date>2025-03-17T10:07:03Z</dc:date>
    </item>
    <item>
      <title>Re: How to find network scanners via stealthwatch</title>
      <link>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5271973#M1166</link>
      <description>&lt;P&gt;yes&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 10:10:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5271973#M1166</guid>
      <dc:creator>dijix1990</dc:creator>
      <dc:date>2025-03-17T10:10:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to find network scanners via stealthwatch</title>
      <link>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5272039#M1167</link>
      <description>&lt;P&gt;While a host generating a ping scan (and no other behaviors) will accrue CI points and trigger a High Concern Index alarm, it will not appear in the 'Internal Network Scanners' section of the Visibility Assessment.&amp;nbsp; The Assessment reports on more complex scans where a host is running an address scan or port scan rather than a more simplistic ping sweep.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 13:51:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5272039#M1167</guid>
      <dc:creator>David Salter</dc:creator>
      <dc:date>2025-03-17T13:51:57Z</dc:date>
    </item>
    <item>
      <title>Re: How to find network scanners via stealthwatch</title>
      <link>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5272042#M1168</link>
      <description>&lt;P&gt;So it's very awful and bad. We need to do some researches to find more reliable product&lt;/P&gt;</description>
      <pubDate>Mon, 17 Mar 2025 13:56:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5272042#M1168</guid>
      <dc:creator>dijix1990</dc:creator>
      <dc:date>2025-03-17T13:56:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to find network scanners via stealthwatch</title>
      <link>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5322782#M1232</link>
      <description>&lt;P&gt;I have a question that might fall under this conversation... The visibility Assessment shows hosts in my case. They do have a high CI, which isn't triggered by a ping sweep. What is the purpose of "Network Scanners" under Configuration? Is it supposed to show the same "rogue" scanners or is it something totally different? In my case it show "&lt;SPAN&gt;The presumed host query has not run. The next query will run at the archive hour. Please check this page again after that time to see any new results.", so I don't know exactly what I am expecting to see.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 09:10:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5322782#M1232</guid>
      <dc:creator>katerina.dardoufa</dc:creator>
      <dc:date>2025-08-21T09:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to find network scanners via stealthwatch</title>
      <link>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5322807#M1233</link>
      <description>&lt;P&gt;The Network Scanners page highlights all hosts that have been detected as exhibiting scanning behavior. From this page, hosts that are known vulnerability scanners or other tools that exhibit scanning behavior as part of their normal operation (such as SNMP polling tools) can be easily classified as scanners directly from the report using the check box to select multiple hosts or the 'Add' button for individual hosts. If different policies are required for different scanning tools, hosts can be moved to different groups with specific polices set as required.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Other hosts that have been identified can be investigated further and appropriate action can be taken.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;A sample screenshot is shown below.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DavidSalter_0-1755771934280.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/250674iBFCDEBA879EA3C32/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DavidSalter_0-1755771934280.png" alt="DavidSalter_0-1755771934280.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Aug 2025 10:32:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5322807#M1233</guid>
      <dc:creator>David Salter</dc:creator>
      <dc:date>2025-08-21T10:32:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to find network scanners via stealthwatch</title>
      <link>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5323109#M1236</link>
      <description>&lt;P&gt;I have already configured the "Network Scanners" in the host group. Shouldn't these appear in the Network Scanner report? Or if they are already categorized they will not show up?&lt;/P&gt;&lt;P&gt;Does the message "&lt;SPAN&gt;The presumed host query has not run. The next query will run at the archive hour. Please check this page again after that time to see any new results." indicate that something is not working as expected?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 07:07:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5323109#M1236</guid>
      <dc:creator>katerina.dardoufa</dc:creator>
      <dc:date>2025-08-22T07:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to find network scanners via stealthwatch</title>
      <link>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5323190#M1237</link>
      <description>&lt;P&gt;You can confirm scanners by checking Hosts → Host Report for detailed flows and security events. If you need faster detection, adjust the scan thresholds in Stealthwatch policy or use custom reports/alarms to flag even short scans. This way, your host activity will also appear in Internal Scanners.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 10:25:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5323190#M1237</guid>
      <dc:creator>Pradyumna14</dc:creator>
      <dc:date>2025-08-22T10:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to find network scanners via stealthwatch</title>
      <link>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5323243#M1238</link>
      <description>&lt;P&gt;If you have not yet applied a policy to the Network Scanners Host Group they will still be reported as scanners.&amp;nbsp; You will need to tune the group to reduce false positives. You may also want to set a 'Low Traffic' threshold too which will alert to scanners not operating as normal.&lt;BR /&gt;&lt;BR /&gt;If you are still seeing the host query message, something is not working as expected.&amp;nbsp; I suggest opening a TAC case so that can be investigated further.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Aug 2025 12:33:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/security-analytics/how-to-find-network-scanners-via-stealthwatch/m-p/5323243#M1238</guid>
      <dc:creator>David Salter</dc:creator>
      <dc:date>2025-08-22T12:33:22Z</dc:date>
    </item>
  </channel>
</rss>

