{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/advanced-ip-scanner/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SoftPerfect Network Scanner","Advanced IP Scanner","Advanced Port Scanner"],"_cs_severities":["medium"],"_cs_tags":["discovery","reconnaissance","windows","endpoint-detection"],"_cs_type":"advisory","_cs_vendors":["SoftPerfect","Famatech"],"content_html":"\u003cp\u003ePost-compromise reconnaissance relies heavily on tools that can quickly enumerate network assets, open ports, and reachable services. Threat actors consistently abuse legitimate, dual-use administrative utilities, specifically SoftPerfect Network Scanner and Advanced IP/Port Scanner, to gain situational awareness within a victim network. These tools are lightweight, portable, and often overlooked by security controls because they are signed, legitimate software.\u003c/p\u003e\n\u003cp\u003eThe use of these tools is a well-documented precursor to lateral movement and ransomware deployment, as seen in various intrusion case studies, including those associated with the RansomHub and BlackByte operations. Defenders should focus on baseline monitoring to identify these binaries when they are introduced into an environment for the first time or executed from non-standard locations, as this behavioral shift often indicates an adversary attempting to map the environment after gaining initial access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful reconnaissance with these tools enables attackers to identify critical infrastructure, domain controllers, and high-value servers. If left undetected, this mapping activity facilitates efficient lateral movement, privilege escalation, and data exfiltration, ultimately increasing the likelihood of widespread ransomware deployment or persistent data theft within the targeted organization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of \u0026quot;newly seen\u0026quot; processes within your environment to catch baseline deviations.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEnable process creation logging via Sysmon (Event ID 1) or Windows Security Event Logs to capture the execution of scanning binaries mentioned in the Sigma rules below.\u003c/li\u003e\n\u003cli\u003eDeploy detection logic to flag the first-time execution of identified scanners on any host within the infrastructure.\u003c/li\u003e\n\u003cli\u003eEstablish a process for analysts to investigate alerts triggered by these scanners to differentiate between authorized IT administrative tasks and unauthorized adversary activity.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-15T12:56:44Z","date_published":"2026-09-14T18:54:55Z","id":"https://feed.craftedsignal.io/briefs/2026-09-newly-seen-network-scanners/","summary":"Adversaries frequently utilize legitimate network scanning utilities like SoftPerfect Network Scanner and Advanced IP Scanner for reconnaissance following initial compromise to map internal network topology and identify lateral movement targets.","title":"Detection of Newly Observed Legitimate Network Scanning Tools","url":"https://feed.craftedsignal.io/briefs/2026-09-newly-seen-network-scanners/"}],"language":"en","title":"CraftedSignal Threat Feed - Advanced IP Scanner","version":"https://jsonfeed.org/version/1.1"}