Detect Network Service Discovery in CrowdStrike LogScale
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation. Common methods include port, vulnerability, and wordlist scans using tools such as nmap, masscan, zmap, CrackMapExec, and custom port scanners. Within cloud environments, adversaries may discover services on other cloud hosts or connected on-premises systems. On macOS, adversaries may leverage Bonjour/mDNSResponder to discover advertised services. Threat actors including Volt Typhoon, APT39, BlackTech, menuPass, FIN13, and ransomware operators like BlackByte routinely perform network service discovery as part of internal reconnaissance before lateral movement.
MITRE ATT&CK
- Tactic
- Discovery
- Technique
- T1046 Network Service Discovery
- Canonical reference
- https://attack.mitre.org/techniques/T1046/
LogScale Detection Query
#event_simpleName=ProcessRollup2
| eval FileName_lower=lower(FileName)
| eval CommandLine_lower=lower(CommandLine)
/* Flag known scanning tool binaries */
| eval KnownScanner=if(
FileName_lower=~"(nmap\.exe|masscan\.exe|zmap\.exe|netscan\.exe|tcping\.exe|superscan\.exe|angryipscan\.exe|nbtscan\.exe|nbtscan-unixwiz\.exe|winegddrop\.exe|rustscan|netdiscover|unicornscan)",
"true", "false"
)
/* Flag native LOLBin scanning patterns */
| eval NativeScan=if(
FileName_lower=~"(powershell\.exe|pwsh\.exe|cmd\.exe)"
AND CommandLine_lower=~"(test-netconnection|tnc |net\.sockets|1\.\.254|1\.\.65535|netstat -a|arp -a|net view|net use\\\\|route print|new-object net\.sockets)",
"true", "false"
)
/* Flag scan-specific flags and port range arguments */
| eval PortScanFlags=if(
CommandLine_lower=~"( -ss | -st | -su | -sv | -sn | -pn |--top-ports|--script |--rate |--ports | -p [0-9])",
"true", "false"
)
/* Exclude known-benign invocations */
| eval ScanExclude=if(
CommandLine_lower=~"(--version|--help|-h |install|update|get-help)",
"true", "false"
)
| where (KnownScanner="true" OR NativeScan="true" OR PortScanFlags="true")
AND ScanExclude!="true"
| eval DetectionType=case(
KnownScanner="true", "KnownScanningTool",
NativeScan="true", "NativeToolScanning",
PortScanFlags="true", "PortScanFlags",
true(), "Unknown"
)
| eval SuspicionScore=if(KnownScanner="true",1,0)+if(NativeScan="true",1,0)+if(PortScanFlags="true",1,0)
| table
@timestamp, ComputerName, UserName,
FileName, CommandLine,
ParentBaseFileName, ParentCommandLine,
KnownScanner, NativeScan, PortScanFlags,
SuspicionScore, DetectionType
| sort @timestamp desc CrowdStrike LogScale (Falcon) query detecting T1046 network service discovery by analysing ProcessRollup2 telemetry from the Falcon sensor. Identifies execution of known scanning tool binaries (nmap, masscan, zmap, tcping, rustscan), native LOLBin scanning constructs in PowerShell and cmd.exe (Test-NetConnection, TCP socket loops, netstat, arp, net view), and explicit nmap-style scan flags. Assigns a suspicion score based on the number of matched risk indicators and excludes common benign invocations such as --version and --help.
Data Sources
Required Tables
False Positives & Tuning
- CrowdStrike Spotlight or third-party EDR/vulnerability scanner integrations that call nmap or masscan via the Falcon RTR response interface during authorised host assessment workflows
- IT operations teams using PowerShell scripts with Test-NetConnection or New-Object Net.Sockets loops to build network dependency maps or validate ACLs after infrastructure changes
- Scheduled task or service account automation that runs netstat, arp -a, or route print as part of daily inventory collection feeding a CMDB or IPAM solution
Other platforms for T1046
Testing Methodology
Validate this detection against 5 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1nmap SYN Scan Against Local Subnet
Expected signal: Sysmon Event ID 1: Process Create with Image ending in nmap.exe, CommandLine containing '-sV -p' and '127.0.0.1'. Sysmon Event ID 3: Multiple network connection events from nmap.exe to 127.0.0.1 on specified ports. Sysmon Event ID 11: File created at %TEMP%\df00tech-nmap-test.txt. Security Event ID 4688 (if process command-line auditing enabled) showing nmap.exe process creation.
- Test 2PowerShell TCP Port Scan via .NET Socket Loop
Expected signal: Sysmon Event ID 1: Process Create for powershell.exe with CommandLine containing 'Net.Sockets.TcpClient' and 'Connect'. Sysmon Event ID 3: Multiple network connection events from powershell.exe to 127.0.0.1 on each tested port. PowerShell ScriptBlock Log Event ID 4104 capturing the full socket enumeration script.
- Test 3PowerShell Host Sweep with Test-NetConnection
Expected signal: Sysmon Event ID 1: Process Create for powershell.exe with CommandLine containing '1..5', 'Test-NetConnection', and '-Port 80'. Sysmon Event ID 3: Multiple network connection attempts from powershell.exe to 127.0.0.1 through 127.0.0.5 on port 80. PowerShell ScriptBlock Log Event ID 4104 showing the full ForEach-Object loop.
- Test 4NBTScan NetBIOS Network Discovery
Expected signal: Sysmon Event ID 1: Process Create with Image ending in nbtscan.exe and CommandLine containing a target IP range. Sysmon Event ID 3: UDP connection attempts from nbtscan.exe to target IP on port 137 (NetBIOS Name Service). Security Event ID 4688 with nbtscan.exe process creation if command-line auditing is enabled.
- Test 5Netstat Service Enumeration via CMD
Expected signal: Sysmon Event ID 1: Process Create for cmd.exe with CommandLine containing 'netstat -ano' and 'findstr LISTENING'. Sysmon Event ID 11: File created at %TEMP%\df00tech-netstat.txt containing listening service output. Security Event ID 4688 for cmd.exe process if command-line auditing is enabled.
References (12)
- https://attack.mitre.org/techniques/T1046/
- https://nmap.org/book/man.html
- https://us-cert.cisa.gov/ncas/analysis-reports/ar21-126a
- https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-038a
- https://www.fireeye.com/blog/threat-research/2019/01/apt39-iranian-cyber-espionage-group-focused-on-personal-information.html
- https://learn.microsoft.com/en-us/defender-endpoint/advanced-hunting-devicenetworkevents-table
- https://learn.microsoft.com/en-us/defender-endpoint/advanced-hunting-deviceprocessevents-table
- https://docs.splunk.com/Documentation/SplunkCloud/latest/SearchReference/CommonStatsFunctions
- https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1046/T1046.md
- https://github.com/SigmaHQ/sigma/tree/master/rules/windows/process_creation
- https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/palmerworm-blacktech-espionage-apt
- https://unit42.paloaltonetworks.com/stately-taurus-toneshell-september-2023/
Unlock Pro Content
Get the full detection package for T1046 including response playbook, investigation guide, and atomic red team tests.