Defender Scans trigger IDS Appliance for port 445 sniffing

  • Thread starter Thread starter Guest
  • Start date Start date
G

Guest

Anyone seen this?
When defender hits the "my network places" folder, it starts firing up TCP
connections and tickling whatever the links inside point to.

This is triggering an IDS box run by the networking guys and shutting down
the users port on the switch.

I am wondering if this behavior is by design or is it a nasty by-product of
something else. I personally do not understand why Defender would need to do
this.
 
Hi Stephen.

No answer for you but I just created a post ("Windows Defender and IIS")
which I think is trying to say the same thing. In my case I believe it is
starting IIS on my computer and using that to tickle available network places
during a scan.
 
Back
Top