We've got SMBv1 Auditing enabled on our domain and SMBv1 disabled on everything including the Lansweeper scan servers.
We're seeing event log entries on our DCs from both of our scan servers like the one below. Nothing else is generating these events, just the scan servers. Judging by the timings it looks like it's IP range scanning that is triggering it.
--------------------------
Log Name: Microsoft-Windows-SMBServer/Audit
Source: Microsoft-Windows-SMBServer
Date: 5/30/2023 7:10:10 AM
Event ID: 3000
Task Category: None
Level: Information
Keywords:
User: N/A
Computer: DC01.Domain.Local
Description:
SMB1 access
Client Address: SCANServer01
--------------------------
Is there any way we can prevent scans from triggering this?