OpenCanary Application Logs: Nmap FIN Scan Targeting (Logtype 5005)
Detects Nmap FIN scan targeting against an OpenCanary node using application logs with logtype 5005.
- Product
- opencanary
- Category
- application
- Author
- Marco Pedrinazzi (@pedrinazziM) (SigmaHQ), DRL 1.1
- Published
- 2026-01-06
- Updated
- 2026-07-31
ATT&CK techniques
DiscoveryRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags OpenCanary instances where the service records activity consistent with an Nmap FIN scan targeting the node. FIN scans are a common reconnaissance technique used to probe network services while attempting to evade more conspicuous scan signatures. Detection relies on OpenCanary application telemetry indicating the specific event logged as logtype 5005.
Reporting behind it
- opencanary.readthedocs.iohttps://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration
- github.comhttps://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/application/opencanary/opencanary_portscan_nmap_fin_scan.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "OpenCanary Application Logs: Nmap FIN Scan Targeting (Logtype 5005)"
id: bfb7c413-36e6-423d-be7f-90587fcfc018
status: experimental
description: This rule flags OpenCanary instances where the service records activity consistent with an Nmap FIN scan targeting the node. FIN scans are a common reconnaissance technique used to probe network services while attempting to evade more conspicuous scan signatures. Detection relies on OpenCanary application telemetry indicating the specific event logged as logtype 5005.
references:
- https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration
- https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52
- https://github.com/SigmaHQ/sigma/blob/master/rules/application/opencanary/opencanary_portscan_nmap_fin_scan.yml
author: Marco Pedrinazzi (@pedrinazziM), Huntrule Team
date: 2026-01-06
tags:
- attack.discovery
- attack.t1046
logsource:
category: application
product: opencanary
detection:
selection:
logtype: 5005
condition: selection
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: eae8c0c8-e5da-450a-9d7d-66aa56cd26b6
type: derived