Adding TCP Port Scan Actions

TCP Port Scan Actions are typically used to validate network segmentation or to simulate typical reconnaissance activities like full port scans and services fingerprinting.

  1. Within the Director, click on Library > Actions in the top navigation bar.
  2. Click Add Action and select TCP Port Scan. The Add TCP Action form displays.
  3. Populate the Form.
    1. Name
    2. Description
    3. Attacker location
    4. Ports to be scanned
      • Separate multiple entries with commas
      • Ranges: use a dash (-) in between the first and last port
      • Ports that should show as closed/unreachable: Add a pound sign (#) in front of the port number
    5. Seconds to Sleep between Ports
    6. (Optional) Select Randomize Port Order.
  4. Click Save Port Scan.

    The Action Library displays. A confirmation message that your Action was created successfully is shown and the Action is selected and displayed in the Action preview.

Adding a TCP Port Scan Action

When a TCP port scan cannot reach out on ports configured in the Actor Communication settings, the map reflects no communication. This is likely from a firewall or device recognizing the behavior and preventing it.
  • June 5, 2022
  • April 4, 2024
In This Article