heroui logo

Newly Seen Commonly Abused Network Scanner

Elastic Detection Rules

View Source
Summary
Detects newly observed execution of SoftPerfect Network Scanner or Advanced IP/Port Scanner on Windows hosts by monitoring process start events. Triggers when a Windows process starts with netscan*.exe or advanced_ip_scanner*.exe (or related file names). The rule uses a new_terms approach to identify previously unseen scanner binaries, across Elastic Defend, Windows Event Logs, Sysmon, CrowdStrike, M365 Defender, SentinelOne Cloud Funnel, and other sources. It maps to MITRE ATT&CK T1018 (Remote System Discovery) and T1046 (Network Service Discovery) under Discovery, and is designed to detect post-compromise reconnaissance that could enable lateral movement. It runs as a new_terms rule with a history window of 7 days and a lookback of 9 minutes for ingested data.
Categories
  • Endpoint
  • Windows
Data Sources
  • Process
  • Image
ATT&CK Techniques
  • T1018
  • T1046
Created: 2026-09-10