We have several devices that perform endpoint and network device scanning. As intended, they are scanning prohibited ports to verify they are not open, however the ESCU correlation searches , specifically the "Prohibited network Traffic Allowed" rule, is detecting thousands of these events each day.
How can I prevent notable events from being created in Enterprise Security when the source is one of the scanning devices?
Thank you.
... View more