This detection identifies the presence of portscanner.exe, a known reconnaissance tool within the Chinese Hacktool set, which adversaries deploy to map network topology and identify active services during early intrusion phases. Proactively hunting for this artifact in Azure Sentinel is critical because its low-severity classification often leads to alert fatigue, allowing attackers to establish persistent footholds before triggering higher-priority incident responses.
rule portscanner {
meta:
description = "Chinese Hacktool Set - file portscanner.exe"
author = "Florian Roth"
reference = "http://tools.zjqhr.com/"
date = "2015-06-13"
hash = "1de367d503fdaaeee30e8ad7c100dd1e320858a4"
strings:
$s0 = "PortListfNo" fullword ascii
$s1 = ".533.net" fullword ascii
$s2 = "CRTDLL.DLL" fullword ascii
$s3 = "exitfc" fullword ascii
condition:
uint16(0) == 0x5a4d and filesize < 25KB and all of them
}
This YARA rule can be deployed in the following contexts:
This rule contains 4 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the Chinese Hacktool Set - file portscanner.exe detection rule in an enterprise environment:
Network Baseline Scans by SolarWinds NPM
portscanner.exe within its installation directory (C:\Program Files\SolarWinds\Orion) to map open ports on critical servers.C:\Program Files\SolarWinds\*\portscanner.exe and restrict alerts to only trigger if the process is launched by a non-privileged service account (e.g., exclude runs initiated by the SYSTEM or SolarWindsAgent user).Software Update Deployment via SCCM/MECM
portscanner.exe into the software distribution cache (C:\Windows\CCMCache) to verify firewall rule integrity before applying updates to the production environment.\CCMCache\ or \SoftwareDistribution\ and filter for processes with a parent process of ccmexec.exe (the SCCM agent service), as this indicates a managed deployment rather than unscheduled user activity.IT Asset Inventory Audit by Lansweeper