Windows Process Creation: SoftPerfect netscan.exe Network Scanner Execution
Alerts on execution of SoftPerfect Network Scanner (netscan.exe), a potential network reconnaissance tool.
FreeUnreviewedSigmamediumv1
windows-process-creation-softperfect-netscan-exe-network-scanner-execution-ca387a8e
title: "Windows Process Creation: SoftPerfect netscan.exe Network Scanner Execution"
id: 2ded843f-73f0-44af-aab2-fc808c79fe4f
status: test
description: This rule flags process creation events where the executed binary ends with \netscan.exe and the application is described as SoftPerfect Network Scanner. Network scanning tools can help attackers map reachable hosts and services during reconnaissance. The detection relies on Windows process creation telemetry containing the executable path, plus product and description metadata associated with the binary.
references:
- https://www.protect.airbus.com/blog/uncovering-cyber-intruders-netscan/
- https://secjoes-reports.s3.eu-central-1.amazonaws.com/Sockbot%2Bin%2BGoLand.pdf
- https://www.sentinelone.com/labs/black-basta-ransomware-attacks-deploy-custom-edr-evasion-tools-tied-to-fin7-threat-actor/
- https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/yanluowang-ransomware-attacks-continue
- https://research.nccgroup.com/2022/07/13/climbing-mount-everest-black-byte-bytes-back/
- https://www.bleepingcomputer.com/news/security/microsoft-exchange-servers-hacked-to-deploy-hive-ransomware/
- https://www.softperfect.com/products/networkscanner/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_pua_netscan.yml
author: "@d4ns4n_ (Wuerth-Phoenix), Huntrule Team"
date: 2024-04-25
tags:
- attack.discovery
- attack.t1046
logsource:
category: process_creation
product: windows
detection:
selection:
- Image|endswith: \netscan.exe
- Product: Network Scanner
- Description: Application for scanning networks
condition: selection
falsepositives:
- Legitimate administrator activity
level: medium
license: DRL-1.1
related:
- id: ca387a8e-1c84-4da3-9993-028b45342d30
type: derived
What it detects
This rule flags process creation events where the executed binary ends with \netscan.exe and the application is described as SoftPerfect Network Scanner. Network scanning tools can help attackers map reachable hosts and services during reconnaissance. The detection relies on Windows process creation telemetry containing the executable path, plus product and description metadata associated with the binary.
Known false positives
- Legitimate administrator activity
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.