OpenCanary Application Logs: Nmap FIN Scan Targeting (Logtype 5005)

Detects Nmap FIN scan targeting against an OpenCanary node using application logs with logtype 5005.

FreeReviewedSigma · High · v5
Product
opencanary
Category
application
Author
Marco Pedrinazzi (@pedrinazziM) (SigmaHQ), DRL 1.1
Published
2026-01-06
Updated
2026-07-31
title: "OpenCanary Application Logs: Nmap FIN Scan Targeting (Logtype 5005)"
id: bfb7c413-36e6-423d-be7f-90587fcfc018
status: experimental
description: This rule flags OpenCanary instances where the service records activity consistent with an Nmap FIN scan targeting the node. FIN scans are a common reconnaissance technique used to probe network services while attempting to evade more conspicuous scan signatures. Detection relies on OpenCanary application telemetry indicating the specific event logged as logtype 5005.
references:
  - https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration
  - https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52
  - https://github.com/SigmaHQ/sigma/blob/master/rules/application/opencanary/opencanary_portscan_nmap_fin_scan.yml
author: Marco Pedrinazzi (@pedrinazziM), Huntrule Team
date: 2026-01-06
tags:
  - attack.discovery
  - attack.t1046
logsource:
  category: application
  product: opencanary
detection:
  selection:
    logtype: 5005
  condition: selection
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: eae8c0c8-e5da-450a-9d7d-66aa56cd26b6
    type: derived