BIOC
Informational
✕
Network scanning tool executed
This rule looks for the string nmap in the command line, which indicates that the nmap scanning tool is used to scan a network or a machine.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Discovery
- Status:
- Enabled
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Remote System Discovery (T1018)
Indicator:
Process action type = execution AND target process cmd = *nmap*
Preventable: yes