BIOC
Informational
✕
Installation of networking security tools
A security or penetration testing tool such as wireshark and nmap is being installed.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Discovery
- Status:
- Enabled
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Network Service Discovery (T1046)
Indicator:
Process action type = execution AND target process name = *Wireshark-* , *WiresharkPortable* , *WinPcap_* , *nmap*setup* , *NPFInstall.exe*
Preventable: yes