BIOC
Informational
✕
Possible ARP reconnaissance
The ARP binary could be used for network mapping (common with malware).
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Discovery
- Status:
- Enabled
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Remote System Discovery (T1018) System Network Configuration Discovery (T1016)
Indicator:
Process action type = execution AND target process name = arp.exe AND process execution signature = Signed AND process execution signer = Microsoft Corporation Host host os = windows
Preventable: yes