Suspicious Nmap Scanner Probe URIs in HTTP Requests (via webserver)

PremiumReviewedSigma · Medium · v1
Category
webserver
Author
HuntRule
Published
2026-09-16
Updated
2026-09-16

ATT&CK techniques

Recon → Discovery
  1. Resource Dev

  2. Initial Access

  3. Execution

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects HTTP requests to characteristic Nmap probe paths used by NSE scripts to fingerprint web servers and Hadoop or application endpoints. Requests for these signature URIs indicate automated scanning and service discovery against exposed infrastructure. Catching the probe paths reveals reconnaissance even when the scanner user-agent has been altered.

Related detections9 linkedT1046 — drag to rearrange
Suspicious Internet Scanning for Docker and Kubelet Ports via masscan
Suspicious Fscan Internal Network Scanner Execution (via process_creation)
Possible Network Service Scanning via Nmap or Masscan (via process_creation)
Malicious Anonymous Login - Domain Specified (via security)
Suspicious Cisco ASA WebVPN Login Scanning with Spoofed Chrome User-Agent
Suspicious Network Scanning Tool Execution
Malicious RDP Discovery Performed on Multiple Hosts (via rdp)
Malicious Anonymous Access Performed to Multiple Targets (via security)
Malicious Network Login Performed to Multiple Targets (via security)
Suspicious Nmap Scanner Probe URIs in HTTP Requests (via webserver)
Pivot detection · T1046 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.