OpenCanary application logs: detect NMAP XMAS scans targeting an OpenCanary node
Detects OpenCanary log events showing an Nmap Xmas scan targeting the monitored node.
FreeReviewedSigma · High · v5
- Product
- opencanary
- Category
- application
- Author
- Marco Pedrinazzi (@pedrinazziM) (SigmaHQ), DRL 1.1
- Published
- 2026-01-06
- Updated
- 2026-07-31
ATT&CK techniques
DiscoveryRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags events in OpenCanary application logs where the logtype value indicates an NMAP XMAS scan targeted the monitored node. Such scanning activity is a common reconnaissance technique used to probe services and infer network exposure. The detection relies on OpenCanary telemetry, specifically the recorded application logtype associated with XMAS scan attempts.
Reporting behind it
- opencanary.readthedocs.iohttps://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration
- github.comhttps://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/application/opencanary/opencanary_portscan_nmap_xmas_scan.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
opencanary-network-service-logs-nmap-xmas-scan-targeting-detection-d7553d7b
title: "OpenCanary application logs: detect NMAP XMAS scans targeting an OpenCanary node"
id: 7066665c-62cc-4ca3-afa6-7865ee3a9d14
status: experimental
description: This rule flags events in OpenCanary application logs where the logtype value indicates an NMAP XMAS scan targeted the monitored node. Such scanning activity is a common reconnaissance technique used to probe services and infer network exposure. The detection relies on OpenCanary telemetry, specifically the recorded application logtype associated with XMAS scan attempts.
references:
- https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration
- https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52
- https://github.com/SigmaHQ/sigma/blob/master/rules/application/opencanary/opencanary_portscan_nmap_xmas_scan.yml
author: Marco Pedrinazzi (@pedrinazziM), Huntrule Team
date: 2026-01-06
tags:
- attack.discovery
- attack.t1046
logsource:
category: application
product: opencanary
detection:
selection:
logtype: 5004
condition: selection
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: d7553d7b-f485-479c-b192-cdac6edd83a4
type: derived