Imagine that an external IP address attempts to connect to port 443 on your public network.
There is nothing particularly remarkable about that. HTTPS is exposed by countless organisations and automated systems routinely interact with it.
Now imagine that the same source tries port 22, then 3389, then 445, then several high-numbered ports within a short period. Shortly afterwards, it begins probing another public IP address belonging to the same organisation.
The context has changed.
If the activity stops there, it may still be an automated internet-wide scanner. But if the same source returns later and focuses specifically on one of the services that responded, the behaviour becomes more interesting.
Add repeated authentication attempts against that service and the situation changes again.
What initially appeared to be an ordinary scan may now form a sequence:
discovery → service identification → targeted activity → access attempt
No individual event necessarily proves that an intrusion is underway. The sequence, however, deserves a very different level of attention from an isolated connection attempt.
Repetition can reveal intent
Frequency is one of the most useful pieces of context when evaluating reconnaissance.
A source that touches your infrastructure once and disappears is different from one that returns repeatedly. The same applies to breadth. An IP address attempting one connection is different from an address systematically testing dozens of ports or multiple systems.
Timing also matters.
Scanning hundreds of ports within seconds can be easy to recognise, but reconnaissance does not always happen quickly. Activity can be deliberately spread over longer periods to make it less obvious. A few probes today, another set tomorrow and additional activity several days later may appear unrelated if every event is examined individually.
This is one reason why historical visibility matters.
If security monitoring only considers what happened during the last few minutes, repeated low-volume activity may disappear into normal network noise. When events can be connected across a longer period, behaviour that looked insignificant in isolation can become much easier to recognise.