PSAD — port scan detection

Installed, but the service is not running. Start it and enable autostart:
sudo systemctl enable --now psad
How to set up (FAQ)
PSAD
Not running
PSAD — port scan detection
Sources
6
Sources
Auto-bans
0
Auto-bans
Max threat
5
on a 1–5 scale
Top scan sources
IPThreatPackets
198.51.100.11 5 87
198.51.100.16 4 2,085
198.51.100.12 4 1,259
198.51.100.14 4 235
198.51.100.13 3 2,392
198.51.100.15 3 195

Port scan detection that Fail2ban does not cover

Fail2ban watches services and reacts to failed logins. It cannot see someone who never tries to log in — an address that sweeps your ports looking for something to talk to leaves no failed authentication behind, so no jail fires. PSAD fills that gap by reading iptables log entries for traffic that was dropped, and grading what it finds.

This page shows the addresses PSAD has flagged, the danger level it assigned each one, how many packets they sent and which ports they went after. The danger level runs from one to five and is worth reading in context: a single probe against a closed port is background noise on any public address, while a methodical sweep across hundreds of ports from one source usually precedes an attempt at whatever it finds open.

PSAD needs a logging rule in your firewall to see anything at all, which is the usual reason it reports nothing on a fresh install. The UFW page in this panel shows whether that logging is in place.