PUA - Nmap/Zenmap Execution

 Original Source: [Sigma source]
Title: PUA - Nmap/Zenmap Execution
Status: test
Description:Detects usage of namp/zenmap. Adversaries may attempt to get a listing of services running on remote hosts, including those that may be vulnerable to remote software exploitation
References:
  -https://nmap.org/
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1046/T1046.md#atomic-test-3---port-scan-nmap-for-windows
Author: frack113
Date: 2021-12-10
modified:2023-12-11
Tags:
  • -'attack.discovery'
  • -'attack.t1046'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    - Image|endswith:
      - '\nmap.exe'
      - '\zennmap.exe'
    - OriginalFileName:
      - 'nmap.exe'
      - 'zennmap.exe'
  condition:selection
Falsepositives:
  -Legitimate administrator activity
Level: medium