Techniques
Sample rules
Nmap Process Activity
- source: elastic
- technicques:
Description
Nmap was executed on a Linux host. Nmap is a FOSS tool for network scanning and security testing. It can map and discover networks, and identify listening services and operating systems. It is sometimes used to gather information in support of exploitation, execution or lateral movement.
Detection logic
event.category:process and event.type:(start or process_started) and process.name:nmap