Network Analysis - Web Shell
What is the IP responsible for conducting the port scan activity?
Port scanning is done for TCP ports.
In order to see the port scan activity, we have to to go Statistics > Conversations > TCP
.
Answer
10.251.96.4
What is the port range scanned by the suspicious host?
Let's sort Port B
in an ascending order.
We can see that the last port scanned is 1024.