#Netscan
I love all the made-up search engines like WebFind and NetScan and Fargle.
November 18, 2024 at 10:50 PM
🎉New report out Monday 11/17 by @Friffnz, Daniel Casenove & @MittenSec!

"In this case, Netscan was run with domain administrator privileges, so all discovered shares were writable. As a result, NetScan was able to create and delete the delete[.]me file on each...

1/2
November 15, 2025 at 6:01 PM
July 13, 2026 at 10:46 PM
🚨 Search for software, end up getting ransomware!

SEO-driven #Bumblebee malware campaigns observed throughout July led to domain compromise, data theft & #Akira ransomware. Tools included #AdaptixC2 & #Netscan.

thedfirreport.com/2025/08/05/f...
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
Overview Bumblebee malware has been an initial access tool used by threat actors since late 2021. In 2023 the malware was first reported as using SEO poisoning as a delivery mechanism. Recently in …
thedfirreport.com
August 5, 2025 at 12:39 PM
What I learnt today:

When NetScan is executed with the ‘Check for write access’ option enabled, a ‘delete[.]me’ file is created then deleted on discovered shares.[1]

Thanks, TheDFIRReport - this is exactly what we are seeing in a recent case. I owe you one 🍻

[1] thedfirreport.com/2025/02/24/c...
Confluence Exploit Leads to LockBit Ransomware
Key Takeaways The intrusion began with the exploitation of CVE-2023-22527 on an exposed Windows Confluence server, ultimately leading to the deployment of LockBit ransomware across the environment.…
thedfirreport.com
July 16, 2025 at 3:21 PM
Tool Tuesday: SoftPerfect NetScan

A legitimate network scanner, and a threat-actor favorite. Across our cases, actors use NetScan to map hosts, shares, and open ports right before lateral movement, sometimes launching…

— from @TheDFIRReport (https://x.com/TheDFIRReport/status/2087230155030769937)
August 11, 2026 at 5:51 PM
NetScan Pro audits network environments by discovering live hosts, mapping subnets, and identifying open ports and vulnerabilities.
July 13, 2026 at 10:46 PM
Cómo encontrar dispositivos 🔍 ¡Descubre quién roba tu WiFi ya! 📶
¿Tu WiFi va lento? 🚀 Descubre quién usa tu red con apps como Fing, Wifi Inspector o NetScan. ¡Controlá tus dispositivos conectados y protegé tu conexión fácil y rápido! 📱🔒 #WiFiSeguro #Redes #Tecnología
Cómo encontrar dispositivos 🔍 ¡Descubre quién roba tu WiFi ya! 📶
Cómo encontrar dispositivos 📱 7 apps fáciles para vigilar tu red WiFi 🚀 Tod@s tenemos conectividad WiFi en casa y
mastertrend.info
June 16, 2026 at 4:00 AM
How Hackers Abuse NetScan’s ‘deleteme’ File for Lateral Movement

Introduction: NetScan, a common network reconnaissance tool, has a lesser-known feature that attackers exploit: the ‘Check for write access’ option creates and deletes a temporary `delete[.]me` file on discovered shares. This…
How Hackers Abuse NetScan’s ‘deleteme’ File for Lateral Movement
Introduction: NetScan, a common network reconnaissance tool, has a lesser-known feature that attackers exploit: the ‘Check for write access’ option creates and deletes a temporary `delete[.]me` file on discovered shares. This technique, recently linked to LockBit ransomware campaigns, enables threat actors to validate permissions before deploying malware. Here’s how to detect and mitigate it. Learning Objectives: Understand how NetScan’s ‘delete.me’ file facilitates lateral movement.
undercodetesting.com
July 16, 2025 at 4:11 PM
3. 攻撃の詳細 攻撃者はNetscanやAdFindなどのツールを使用してネットワーク内のホストやアカウントを探索し、資格情報を収集しました。さらに、PsExecを使用して各ホストにランサムウェアを展開し、Windows Defenderを無効化した後、ファイルを暗号化しました。
July 19, 2024 at 12:50 AM
"SoftPerfect NetScan was used extensively during the intrusion… evidence from Security Event ID 4688 logs showed mstsc.exe /v: being launched by netscan.exe, confirming the use of NetScan’s Remote Desktop functionality."

Full report 👇
thedfirreport.com/2025/11/17/c...
February 25, 2026 at 6:19 PM
ネットワークスキャン・セキュリティ評価ツール「NetScan Pro」のご紹介: NECセキュリティブログ | NEC https://jpn.nec.com/cybersecurity/blog/250523/index.html
May 23, 2025 at 2:42 AM
📦 New in #nixpkgs (2026-06-01):

• essh (#526645)
• netscan (#526513)
• diskwatch (#526507)
• syswatch (#526500)
• whichllm (#522384)
• python3Packages.quack-kernels (#526459)
• cudaPackages_13_3 (#525130)
• vimPlugins.jujutsu-nvim (#526606)
• vimPlugins.neotest-bun (#526601)


Full list on GitHub
June 2, 2026 at 1:54 AM
The latest update for #PandoraFMS includes "New Discovery with NetScan for Automated Asset Management in Pandora FMS NG 781 RRR" and "#Monitoring in Hyperconverged Infrastructures: Challenges and Solutions".

#uptime https://opsmtrs.com/3iYd3zG
Pandora FMS
A single monitoring solution to control your business. With just one tool, you can monitor any device, infrastructure, application, service and business process.
opsmtrs.com
March 12, 2025 at 4:00 AM
"SoftPerfect NetScan was used extensively during the intrusion… evidence from Security Event ID 4688 logs showed mstsc.exe /v: being launched by netscan.exe, confirming the use of NetScan’s Remote Desktop f…

— from @TheDFIRReport (https://x.com/TheDFIRReport/status/2026723627224211471)
February 25, 2026 at 6:34 PM
I feel like this should be possible if you get a memory dump using something like Volatility, then “netscan” or look for weird connections. Although, if the attackers put any effort into obfuscating the traffic, might be kind of hard
November 27, 2024 at 6:22 PM