Port Sweep on port 445 and 5986 from ntoskrnl.exe

Aasik Ali 0 Reputation points
2024-03-18T07:24:44.3+00:00

I noticed a port sweep connection by ntkrnlmp.exe. Alerts are getting generated everyday in SIEM Sentinel. We discovered an internal source IP (private) attempting to connect to numerous internal private IP addresses over port 445 and port 5986(WinRM).

_Im_NetworkSession table in sentinel capturing these logs under DeviceNeworkEvents. Initiating process is 'ntkrnlmp.exe' It's likely that some system-level processes or services are utilizing network resources, possibly for legitimate purposes like system management, updates, or communication with other systems. But not sure what is causing this issue.

Windows for business | Windows Client for IT Pros | Networking | Network connectivity and file sharing
Windows for business | Windows Server | User experience | Other
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.