Question Saftey of using Symantec endpoint protection

Please provide comments and solutions that are helpful to the author of this topic.

Parkinsond

Level 18
Thread author
Dec 6, 2023
889
SEP keeps reporting attempts for port scanning from different IP addresses, which get blocked.
What does it mean?
Capture2.PNG
Capture1.PNG
 
  • Like
Reactions: Sorrento

Bot

AI-powered Bot
Apr 21, 2016
5,175
It means Symantec Endpoint Protection (SEP) is detecting and blocking attempts by external IP addresses to identify open ports in your system - a common precursor to cyber attacks. It's a sign that SEP is doing its job protecting your network.
 

Parkinsond

Level 18
Thread author
Dec 6, 2023
889
It means Symantec Endpoint Protection (SEP) is detecting and blocking attempts by external IP addresses to identify open ports in your system - a common precursor to cyber attacks. It's a sign that SEP is doing its job protecting your network.
Any further measures needed?
 

Bot

AI-powered Bot
Apr 21, 2016
5,175
Any further measures needed?
While SEP is effectively blocking these attempts, it's always a good idea to ensure your software is up to date, enforce strong password policies, and educate users about phishing scams. Regularly monitor your logs to identify any persistent or suspicious activity.
 

Parkinsond

Level 18
Thread author
Dec 6, 2023
889
Do you have any torrent application running while getting these alerts? Or any other pc in your lan has torrent application running ?
No; I do not use torrent at all.
Modem router is connected only to my PC and another turned off one by cable.
 

Vitali Ortzi

Level 31
Verified
Top Poster
Well-known
Dec 12, 2016
2,052
Modem router is connected only to my PC and another turned off one by cable.
You have the IP address check it and look where the traffic is coming from
Maybe it's malicious maybe not but usually software shouldn't scan for active ports if default ones are open
So it is suspicious but not necessarily malicious
 

Brahman

Level 19
Verified
Top Poster
Well-known
Aug 22, 2013
912
No; I do not use torrent at all.
Modem router is connected only to my PC and another turned off one by cable.
Check whether your router has firewall functionality? If so check whether it's properly configured or not. Do you have static IP address or dynamic ip address from your isp? If you have a dynamic ip address, your isp would be shielding your ports from their side. You can test it's integrity by going to GRC | ShieldsUP! — Internet Vulnerability Profiling. You can also consider a hardware firewall like opnsense or pfsense, mikrotik hap ac3 etc for added protection.
 

Parkinsond

Level 18
Thread author
Dec 6, 2023
889
You have the IP address check it and look where the traffic is coming from
Maybe it's malicious maybe not but usually software shouldn't scan for active ports if default ones are open
So it is suspicious but not necessarily malicious
How can I check such IP addresses?
 

Parkinsond

Level 18
Thread author
Dec 6, 2023
889
Check whether your router has firewall functionality? If so check whether it's properly configured or not. Do you have static IP address or dynamic ip address from your isp? If you have a dynamic ip address, your isp would be shielding your ports from their side. You can test it's integrity by going to GRC | ShieldsUP! — Internet Vulnerability Profiling. You can also consider a hardware firewall like opnsense or pfsense, mikrotik hap ac3 etc for added protection.
My modem router firewall is set to max.
My IP is dynamic.
This is the test result.
Screenshot_1-6-2025_121847_www.grc.com.jpeg
 

Brahman

Level 19
Verified
Top Poster
Well-known
Aug 22, 2013
912
There is some more tests under that, do that too. You can check specific port range too.
 

Brahman

Level 19
Verified
Top Poster
Well-known
Aug 22, 2013
912
I keep getting more and more logs of port scanning from several IP addresses.
These port scans are not that concerning, it happens all the time. You can switch off your router for some time and restart it so that your isp might issue a new dynamic ip address, with that the port scanning may go away for some time.
 
  • Thanks
Reactions: Parkinsond

Parkinsond

Level 18
Thread author
Dec 6, 2023
889
These port scans are not that concerning, it happens all the time. You can switch off your router for some time and restart it so that your isp might issue a new dynamic ip address, with that the port scanning may go away for some time.
Any way to block trials of port scanning?
 

Parkinsond

Level 18
Thread author
Dec 6, 2023
889
This is the data of one of the IP addresses performing port scanning.
And I have noticed Google search was blocked for few minutes!
Screenshot_1-6-2025_131148_whatismyipaddress.com.jpeg
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top