Passive Sensor Templates

The following table describes the characteristics of the predefined passive sensor templates.

Property Recommended Strict detection OT / Edge Data center Medical
Description This template contains the settings recommended by Forescout Professional Services. Medium detection verbosity. Template allowing for detection of all alerts Optimized for sensors deployed at ICS supervisory network level, with a mix of IT and OT protocols Optimized for sensors deployed at data center/core network location, with high throughput and prevalence of IT traffic Optimized for sensors deployed at medical facilities, with prevalence of IT traffic and default medical SD scripts loaded in
Portscan
  • Portscan settings: disable SYN, ACK, maimon and OOS scans
  • Set the FIN Scans to 20 packets
Everything enabled as per each engine default Everything enabled as per each engine default Disabled Disabled
Man in the middle ARP Poisoning settings: 10 packets, 60 seconds, threshold 6 seconds Everything enabled as per each engine default. ICMP redirect disabled Disabled Disabled
ITL Everything enabled as per each engine default. Everything enabled as per each engine default + public IPs communications All ITL detection is enabled as per engine default except for devices with many failed connection attempts - increased to 30 per 60 seconds All the ITL detection is enabled as per engine default except for:
  • Device with many failed connection attempts - disabled
  • Malicious file transfer - disabled (for performance reasons)
  • Many checks are disabled indirectly due to disabled protocols
All the ITL detection is enabled as per engine default except for:
  • Device with many failed connection attempts - disabled
  • Malicious file transfer - disabled (for performance reasons)
  • Many checks are disabled indirectly due to disabled protocols
Protocols, Malformed Packet Detection
  • Everything enabled as per Malformed Packet engine default
  • All protocols recognition/parsing enabled
  • Everything enabled as per Malformed Packet engine default
  • All protocols recognition/parsing enabled
  • All L2/L3/L4 malformed packet checks disabled
  • All protocols recognition/parsing enabled
  • All L2/L3/L4 malformed packet checks disabled
  • IT and IoT/BAS protocols recognition and parsing enabled
  • Selected standard OT protocols enabled, but with parsing disabled
  • OT / DCS proprietary protocols disabled
  • All L2/L3/L4 malformed packet checks disabled
  • IT and IoT/BAS protocols recognition and parsing enabled
  • Selected standard OT protocols enabled, but with parsing disabled
  • OT / DCS proprietary protocols disabled
FEA 15 alerts - time window 300 - stop after 5 windows

 

Special settings:
  • dpbi_* and lan_* alerts: once a day 1 event, 86400 seconds, stop after 0 time windows
  • pars_psc_* alerts: once a day 1 event, 86400 seconds, stop after 0 time windows
  • portscan: once an hour 1 event, 3600 seconds, stop after 0 time windows
  • SNMP, itl_sec_udb_bcred: 5 events, 3600 seconds, stop after 6 windows
15 alerts - time window 300 - stop after 3 windows 10 alerts - time window 360 - stop after 5 windows

 

Special settings:
  • dpbi_* and lan_* alerts: 2 events, 3600 seconds, stop after 6 windows
  • pars_psc_* alerts: 5 events, 3600 seconds, stop after 6 windows
  • SNMP and itl_sec_udb_bcred: 5 events, 3600 seconds, stop after 6 windows
5 alerts - time window 360 - stop after 5 windows

 

Special settings:
  • dpbi_* and lan_* alerts: 2 events, 3600 seconds, stop after 6 windows
  • pars_psc_* alerts: 5 events, 3600 seconds, stop after 6 windows
  • SNMP and itl_sec_udb_bcred: 5 events, 3600 seconds, stop after 6 windows
5 alerts - time window 360 - stop after 5 windows

 

Special settings:
  • dpbi_* and lan_* alerts: 2 events, 3600 seconds, stop after 6 windows
  • pars_psc_* alerts: 5 events, 3600 seconds, stop after 6 windows
  • SNMP and itl_sec_udb_bcred: 5 events, 3600 seconds, stop after 6 windows
Visual Analytics Enabled; netflow disabled Enabled; netflow disabled Enabled; netflow disabled
  • Enabled; netflow disabled
  • Removed OSISOFT PI, NFS, X11 port based recognition
  • Enabled; netflow disabled
  • Removed OSISOFT PI, NFS, X11 port based recognition
LAN CP No profiles created No profiles created No profiles created No profiles created No profiles created
SD Scripts
  • Threat Detection Add-Ons v25.12.16
  • OT Device Visibility Add-Ons v25.12.22
  • Device Visibility Add-Ons v26.01.26
  • Threat Detection Add-Ons v25.12.16
  • OT Device Visibility Add-Ons v25.12.22
  • Device Visibility Add-Ons v26.01.26
  • Threat Detection Add-Ons v25.12.16
  • OT Device Visibility Add-Ons v25.12.22
  • Device Visibility Add-Ons v26.01.26
Device Visibility Add-Ons v26.01.26
  • Healthcare Device Visibility Add-Ons v26.01.26
  • Device Visibility Add-Ons v26.01.26
  • PTS Translogic Monitor v25.05.23
  • GE_RWHAT Monitor v25.05.23
  • Philips Data Export Monitor v25.05.23
  • POCT1-A Monitor v25.05.23
  • LIS2 Monitor v25.10.06
Event logging All events enabled All events enabled All events enabled DNS Name Query paused (to avoid Analytics overload, Name Resolved remains)
  • DNS Name Query paused (to avoid Analytics overload, Name Resolved remains)
  • DICOM events enabled
Sensor advanced settings
  • Disabled processing of TCP hotstarts
  • IPv6 processing and ERSPAN processing enabled
IPv6 processing and ERSPAN processing enabled IPv6 processing and ERSPAN processing enabled
  • Disabled processing of TCP hotstarts
  • Disabled "Include PCAP on alert data"
  • IPv6 processing and ERSPAN processing enabled
  • Disabled processing of TCP hotstarts
  • Disabled "Include PCAP on alert data"
  • IPv6 ERSPAN processing enabled