r/threatintel
One KQL query for the three network scanners that show up across 45+ ransomware groups
- upvotes
- 9
- comments
- 2
Post
Highlighted: the lines this signal was extracted from
SoftPerfect NetScan, Advanced IP Scanner and Advanced Port Scanner keep showing up in the discovery phase before encryption. This is the Defender Advanced Hunting query I use to sweep for all three. It matches on PE vendor metadata and the operator flag pairs, not the file name: let CompanyKeywords = dynamic(["Famatech", "SoftPerfect"]); let ProductKeywords = dynamic(["Advanced IP Scanner", "Advanced Port Scanner", "Network Scanner"]); let DescKeywords = dynamic(["Advanced IP Scanner", "Advanced Port Scanner", "Application for scanning networks"]); DeviceProcessEvents | where Timestamp > ago(30d) | where ProcessVersionInfoCompanyName has_any (CompanyKeywords) or ProcessVersionInfoProductName has_any (ProductKeywords) or ProcessVersionInfoFileDescription has_any (DescKeywords) or ProcessCommandLine has_all ("/portable", "/lng") or ProcessCommandLine has_all ("/hide", "/auto") | project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, ProcessVersionInfoCompanyName, ProcessVersionInfoProductName, ProcessVersionInfoFileDescription, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessParentFileName The video walks through it on lab telemetry, plus the Elastic ES|QL version, a tool-agnostic network-sweep query, and how to tell an admin from an operator: https://youtu.be/Iun8zko6EZk