networkThreatDetails:portScanDetails Fields
Man-in-the-Middle port scanning events are returned as
THREAT
events with
type=NETWORK
and a
networkThreatDetails:portScanDetails
block with the following information:
"details": {
...,
"assessments": [...],
"networkThreatDetails": {
"portScanDetails" {
"type": "PORT_SCAN"
}
}
}
Field | Type | Description |
---|---|---|
| String | Always
PORT_SCAN |