
Summary
Detects newly observed execution of SoftPerfect Network Scanner or Advanced IP/Port Scanner on Windows hosts by monitoring process start events. Triggers when a Windows process starts with netscan*.exe or advanced_ip_scanner*.exe (or related file names). The rule uses a new_terms approach to identify previously unseen scanner binaries, across Elastic Defend, Windows Event Logs, Sysmon, CrowdStrike, M365 Defender, SentinelOne Cloud Funnel, and other sources. It maps to MITRE ATT&CK T1018 (Remote System Discovery) and T1046 (Network Service Discovery) under Discovery, and is designed to detect post-compromise reconnaissance that could enable lateral movement. It runs as a new_terms rule with a history window of 7 days and a lookback of 9 minutes for ingested data.
Categories
- Endpoint
- Windows
Data Sources
- Process
- Image
ATT&CK Techniques
- T1018
- T1046
Created: 2026-09-10