Skip to main content
ElasticCustomer feedback

A security researcher mentioned creating an Elastic ES|QL version of a threat hunting query, indicating the platform's use for detecting malicious network scanning activity.

What happened

Post: "One KQL query for the three network scanners that show up across 45+ ransomware groups"

Source

RedditOct 3, 2026By u/securityinbits

r/threatintel

One KQL query for the three network scanners that show up across 45+ ransomware groups

upvotes
9
comments
2

Post

Highlighted: the lines this signal was extracted from

SoftPerfect NetScan, Advanced IP Scanner and Advanced Port Scanner keep showing up in the discovery phase before encryption. This is the Defender Advanced Hunting query I use to sweep for all three. It matches on PE vendor metadata and the operator flag pairs, not the file name: let CompanyKeywords = dynamic(["Famatech", "SoftPerfect"]); let ProductKeywords = dynamic(["Advanced IP Scanner", "Advanced Port Scanner", "Network Scanner"]); let DescKeywords = dynamic(["Advanced IP Scanner", "Advanced Port Scanner", "Application for scanning networks"]); DeviceProcessEvents | where Timestamp > ago(30d) | where ProcessVersionInfoCompanyName has_any (CompanyKeywords) or ProcessVersionInfoProductName has_any (ProductKeywords) or ProcessVersionInfoFileDescription has_any (DescKeywords) or ProcessCommandLine has_all ("/portable", "/lng") or ProcessCommandLine has_all ("/hide", "/auto") | project Timestamp, DeviceName, AccountName, FileName, ProcessCommandLine, ProcessVersionInfoCompanyName, ProcessVersionInfoProductName, ProcessVersionInfoFileDescription, SHA256, InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessParentFileName The video walks through it on lab telemetry, plus the Elastic ES|QL version, a tool-agnostic network-sweep query, and how to tell an admin from an operator: https://youtu.be/Iun8zko6EZk

reddit.com/r/threatintel/comments/1wwo1t8/one_kql_query_for_the_three...Read the full source

Comments on the post

1 of 2 comments
  • “Thanks for sharing!”

    u/ark0x002 points · Oct 4, 2026View

Extracted by Autobound

From the Signal API record
Signal
Customer feedback

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/threatintel

Companies

  • MicrosoftAlso named

The full record

From the Signal API record

Numbers

Mentions
3

Details

Timing
Ongoing state
Category
Features
Virality
Low
Post kind
Multi media
Prominence
Aside
Company's role
Vendor

Topics and mentions

Topics

  • threat hunting
  • security
  • esql

Extraction

Sentiment
Positive
Detected
Oct 3, 2026
signal_type
reddit-company
signal_subtype
customerFeedback

Use this data

Get every Reddit signal for Elastic and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at Elastic this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/eec05626-4a0a-5916-a594-bfbb47aae735 returns this record as JSON. POST /v1/companies/enrich returns every signal for elastic.co.

{
  "signal_id": "eec05626-4a0a-5916-a594-bfbb47aae735",
  "signal_type": "reddit-company",
  "signal_subtype": "customerFeedback",
  "detected_at": "2026-10-03T14:03:29+00:00",
  "company": {
    "name": "Elastic",
    "domain": "elastic.co"
  },
  "data": {
    "nsfw": false,
    "stage": "none",
    "awards": 0,
    "timing": "ongoing_state",
    "topics": [
      "threat hunting",
      "security",
      "esql"
    ],
    "post_id": "1wwo1t8",
    "summary": "A security researcher mentioned creating an Elastic ES|QL version of a threat hunting query, indicating the platform's use for detecting malicious network scanning activity.",
    "category": "features",
    "comments": [
      {
        "url": "https://www.reddit.com/r/threatintel/comments/1wwo1t8/comment/pdpsshh/",
        "depth": 0,
        "score": 2,
        "author": "ark0x00",
        "excerpt": "Thanks for sharing!",
        "posted_at": "2026-10-04T00:34:40.000Z",
        "author_url": "https://www.reddit.com/user/ark0x00/"
      }
    ],
    "evidence": [
      "[post] The video walks through it on lab telemetry, plus the Elastic ES|QL version, a tool-agnostic network-sweep query, and how to tell an admin from an operator: https://youtu.be/Iun8zko6EZk"
    ],
    "virality": "low",
    "post_date": "2026-10-03T14:03:29.000Z",
    "post_kind": "multi_media",
    "post_text": "SoftPerfect NetScan, Advanced IP Scanner and Advanced Port Scanner keep showing up in the discovery phase before encryption. This is the Defender Advanced Hunting query I use to sweep for all three. It matches on PE vendor metadata and the operator flag pairs, not the file name:\nlet CompanyKeywords = dynamic([\"Famatech\", \"SoftPerfect\"]);\nlet ProductKeywords = dynamic([\"Advanced IP Scanner\", \"Advanced Port Scanner\", \"Network Scanner\"]);\nlet DescKeywords = dynamic([\"Advanced IP Scanner\", \"Advanced Port Scanner\", \"Application for scanning networks\"]);\nDeviceProcessEvents\n| where Timestamp > ago(30d)\n| where ProcessVersionInfoCompanyName has_any (CompanyKeywords)\nor ProcessVersionInfoProductName has_any (ProductKeywords)\nor ProcessVersionInfoFileDescription has_any (DescKeywords)\nor ProcessCommandLine has_all (\"/portable\", \"/lng\")\nor ProcessCommandLine has_all (\"/hide\", \"/auto\")\n| project\nTimestamp, DeviceName, AccountName, FileName,\nProcessCommandLine, ProcessVersionInfoCompanyName,\nProcessVersionInfoProductName, ProcessVersionInfoFileDescription,\nSHA256, InitiatingProcessFileName,\nInitiatingProcessCommandLine, InitiatingProcessParentFileName\nThe video walks through it on lab telemetry, plus the Elastic ES|QL version, a tool-agnostic network-sweep query, and how to tell an admin from an operator: https://youtu.be/Iun8zko6EZk",
    "sentiment": "positive",
    "subreddit": "threatintel",
    "post_title": "One KQL query for the three network scanners that show up across 45+ ransomware groups",
    "prominence": "aside",
    "source_url": "https://www.reddit.com/r/threatintel/comments/1wwo1t8/one_kql_query_for_the_three_network_scanners_that/",
    "entity_role": "vendor",
    "post_author": "securityinbits",
    "upvote_ratio": 1,
    "mention_count": 3,
    "mention_surge": true,
    "subreddit_url": "https://www.reddit.com/r/threatintel/",
    "total_upvotes": 9,
    "comments_total": 2,
    "total_comments": 2,
    "other_companies": [
      {
        "name": "Microsoft",
        "role": "alternative",
        "domain": "microsoft.com"
      }
    ],
    "post_author_url": "https://www.reddit.com/user/securityinbits/",
    "signal_category": "feedback",
    "comments_included": 1
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.