Question Saftey of using Symantec endpoint protection

Please provide comments and solutions that are helpful to the author of this topic.
SEP keeps reporting attempts for port scanning from different IP addresses, which get blocked.
What does it mean?
Capture2.PNG
Capture1.PNG
 
  • Like
Reactions: Sorrento
It means Symantec Endpoint Protection (SEP) is detecting and blocking attempts by external IP addresses to identify open ports in your system - a common precursor to cyber attacks. It's a sign that SEP is doing its job protecting your network.
 
It means Symantec Endpoint Protection (SEP) is detecting and blocking attempts by external IP addresses to identify open ports in your system - a common precursor to cyber attacks. It's a sign that SEP is doing its job protecting your network.
Any further measures needed?
 
Any further measures needed?
While SEP is effectively blocking these attempts, it's always a good idea to ensure your software is up to date, enforce strong password policies, and educate users about phishing scams. Regularly monitor your logs to identify any persistent or suspicious activity.
 
Do you have any torrent application running while getting these alerts? Or any other pc in your lan has torrent application running ?
No; I do not use torrent at all.
Modem router is connected only to my PC and another turned off one by cable.
 
Modem router is connected only to my PC and another turned off one by cable.
You have the IP address check it and look where the traffic is coming from
Maybe it's malicious maybe not but usually software shouldn't scan for active ports if default ones are open
So it is suspicious but not necessarily malicious
 
No; I do not use torrent at all.
Modem router is connected only to my PC and another turned off one by cable.
Check whether your router has firewall functionality? If so check whether it's properly configured or not. Do you have static IP address or dynamic ip address from your isp? If you have a dynamic ip address, your isp would be shielding your ports from their side. You can test it's integrity by going to GRC | ShieldsUP! — Internet Vulnerability Profiling. You can also consider a hardware firewall like opnsense or pfsense, mikrotik hap ac3 etc for added protection.
 
You have the IP address check it and look where the traffic is coming from
Maybe it's malicious maybe not but usually software shouldn't scan for active ports if default ones are open
So it is suspicious but not necessarily malicious
How can I check such IP addresses?
 
Check whether your router has firewall functionality? If so check whether it's properly configured or not. Do you have static IP address or dynamic ip address from your isp? If you have a dynamic ip address, your isp would be shielding your ports from their side. You can test it's integrity by going to GRC | ShieldsUP! — Internet Vulnerability Profiling. You can also consider a hardware firewall like opnsense or pfsense, mikrotik hap ac3 etc for added protection.
My modem router firewall is set to max.
My IP is dynamic.
This is the test result.
Screenshot_1-6-2025_121847_www.grc.com.jpeg
 
I keep getting more and more logs of port scanning from several IP addresses.
 
There is some more tests under that, do that too. You can check specific port range too.
 
I keep getting more and more logs of port scanning from several IP addresses.
These port scans are not that concerning, it happens all the time. You can switch off your router for some time and restart it so that your isp might issue a new dynamic ip address, with that the port scanning may go away for some time.
 
  • Thanks
Reactions: Parkinsond
These port scans are not that concerning, it happens all the time. You can switch off your router for some time and restart it so that your isp might issue a new dynamic ip address, with that the port scanning may go away for some time.
Any way to block trials of port scanning?
 
As I said, it's not that dangerous per se as your software firewall blocks it. If you are that concerned get a good hardware firewall.
I am not concerned; I am aksing you if I should 👀
 
This is the data of one of the IP addresses performing port scanning.
And I have noticed Google search was blocked for few minutes!
Screenshot_1-6-2025_131148_whatismyipaddress.com.jpeg