Skip to content
All security projects
Security projectDemo readyRecon detection

Port Scan Lab

Detection lab for identifying Nmap-style port scan and reconnaissance activity from firewall logs.

Parses firewall logs, groups connection attempts by source IP, and detects port scanning patterns: wide port sweeps, mixed-service reconnaissance, and rapid scan windows. Outputs scan findings, per-source risk tables, a Markdown timeline report, and analyst triage handoff.

PythonCLIFirewall logsNmap detection

Catalog entry only — a full write-up lands closer to release.

Related across catalogs

Want a heads-up when Port Scan Lab releases?

Subscribe via blog