BIOC Informational

Possible ARP reconnaissance

The ARP binary could be used for network mapping (common with malware).

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Discovery
Status:
Enabled
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Remote System Discovery (T1018) System Network Configuration Discovery (T1016)
Indicator:

Process action type = execution AND target process name = arp.exe AND process execution signature = Signed AND process execution signer = Microsoft Corporation Host host os = windows

Preventable: yes