Event Id | 15002 |
Source | Microsoft ISA Server Report Generator |
Description | ISA Server detected an Internet Protocol (IP) half scan attack. For more information about this event, see ISA Server Help. For more information about this event, see ISA Server Help. |
Event Information | According to Microsoft Cause: A possible Internet Protocol (IP) half-scan attack was attempted against a computer protected by ISA Server. This alert occurs when an unexpected Transmission Control Protocol (TCP) packet with a particular flag (for example, Fin, Ack, All, None) is detected. Resolution: If logging for dropped packets is enabled, you can view details of this attack in the Firewall log in the log viewer. You can use this log to monitor any further intruder activity. To do this, in the console tree of ISA Server Management click Monitoring, then click the Logging tab. Then edit the log filter to view the relevant details. Take additional steps against intruder activity. For example, you may want to add access rules denying traffic from the source of the intrusion. To do this, in the console tree of ISA Server Management click Firewall Policy. Then, on the Tasks tab, click Create New Access Rule. |
Reference Links | Event Id:15002 Source Id:Microsoft ISA Server Report Generator |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.