<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Advanced IP Scanner - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/advanced-ip-scanner/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 14 Sep 2026 18:54:55 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/advanced-ip-scanner/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Detection of Newly Observed Legitimate Network Scanning Tools</title><link>https://feed.craftedsignal.io/briefs/2026-09-newly-seen-network-scanners/</link><pubDate>Mon, 14 Sep 2026 18:54:55 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-newly-seen-network-scanners/</guid><description>Adversaries frequently utilize legitimate network scanning utilities like SoftPerfect Network Scanner and Advanced IP Scanner for reconnaissance following initial compromise to map internal network topology and identify lateral movement targets.</description><content:encoded><![CDATA[<p>Post-compromise reconnaissance relies heavily on tools that can quickly enumerate network assets, open ports, and reachable services. Threat actors consistently abuse legitimate, dual-use administrative utilities, specifically SoftPerfect Network Scanner and Advanced IP/Port Scanner, to gain situational awareness within a victim network. These tools are lightweight, portable, and often overlooked by security controls because they are signed, legitimate software.</p>
<p>The use of these tools is a well-documented precursor to lateral movement and ransomware deployment, as seen in various intrusion case studies, including those associated with the RansomHub and BlackByte operations. Defenders should focus on baseline monitoring to identify these binaries when they are introduced into an environment for the first time or executed from non-standard locations, as this behavioral shift often indicates an adversary attempting to map the environment after gaining initial access.</p>
<h2 id="impact">Impact</h2>
<p>Successful reconnaissance with these tools enables attackers to identify critical infrastructure, domain controllers, and high-value servers. If left undetected, this mapping activity facilitates efficient lateral movement, privilege escalation, and data exfiltration, ultimately increasing the likelihood of widespread ransomware deployment or persistent data theft within the targeted organization.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification of &quot;newly seen&quot; processes within your environment to catch baseline deviations.</p>
<ul>
<li>Enable process creation logging via Sysmon (Event ID 1) or Windows Security Event Logs to capture the execution of scanning binaries mentioned in the Sigma rules below.</li>
<li>Deploy detection logic to flag the first-time execution of identified scanners on any host within the infrastructure.</li>
<li>Establish a process for analysts to investigate alerts triggered by these scanners to differentiate between authorized IT administrative tasks and unauthorized adversary activity.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>discovery</category><category>reconnaissance</category><category>windows</category><category>endpoint-detection</category></item></channel></rss>