Cyber criminals follow patterns, starting with very low-effort trolling for new services without much defenses. Bots scan the internet for open services, enumerate them, and try to gain access. If they find some, they will use a tiny amount of effort to see if the target might be worth exploring. If it seems profitable, the cybercriminal will spend more effort on things like account enumeration, login brute force, scanning for commonly exploitable methods, phishing. The more they find, the more they're willing to invest in exploiting it. But a bot can perform a ransomware hijacking of a newly detected open service all on its own, so it doesn't take much.
Simple mitigations can be very effective in holding back their interest. Captchas, rate limiters, error pages with no information leakage, block lists of low-reputation IPs, or outright blocks of countries you don't do business with. They make the difference between 50k login attempts per minute, or crickets.
Don't use port knocking tho. It technically works, but is embarrassing, like a grown man in a trilby. Something else (like rate limiting combined with certificate auth) will be more effective and less weird.