Skip to content

Commit c3f97a3

Browse files
committed
Rewrite Advanced IP and Port Scanner Target for Performance and add Favorites
1 parent 9526843 commit c3f97a3

2 files changed

Lines changed: 332 additions & 20 deletions

File tree

Lines changed: 166 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,31 +1,187 @@
11
Description: Advanced IP Scanner Artifacts
22
Author: Reece394
3-
Version: 1.0
3+
Version: 1.1
44
Id: 6b103fca-428f-45a7-a62e-18314d4562d7
55
RecreateDirectories: true
66
Targets:
77
-
8-
Name: Advanced IP Scanner Aliases
8+
Name: Advanced IP Scanner Aliases - User Folder
99
Category: Apps
10-
Path: C:\
10+
Path: C:\Users\%user%
1111
FileMask: 'advanced_ip_scanner_Aliases.bin'
12-
Recursive: true
1312

1413
-
15-
Name: Advanced IP Scanner Comments
14+
Name: Advanced IP Scanner Aliases - User Temp Folder
1615
Category: Apps
17-
Path: C:\
16+
Path: C:\Users\%user%\AppData\Local\Temp\Advanced IP Scanner 2
17+
FileMask: 'advanced_ip_scanner_Aliases.bin'
18+
19+
-
20+
Name: Advanced IP Scanner Aliases - Windows Temp Folder
21+
Category: Apps
22+
Path: C:\Windows\Temp\Advanced IP Scanner 2
23+
FileMask: 'advanced_ip_scanner_Aliases.bin'
24+
25+
-
26+
Name: Advanced IP Scanner Aliases - SYSTEM SysWOW64 User Folder
27+
Category: Apps
28+
Path: C:\Windows\SysWOW64\config\systemprofile
29+
FileMask: 'advanced_ip_scanner_Aliases.bin'
30+
31+
-
32+
Name: Advanced IP Scanner Aliases - SYSTEM User Folder
33+
Category: Apps
34+
Path: C:\Windows\System32\config\systemprofile
35+
FileMask: 'advanced_ip_scanner_Aliases.bin'
36+
37+
-
38+
Name: Advanced IP Scanner Aliases - LocalService User Folder
39+
Category: Apps
40+
Path: C:\Windows\ServiceProfiles\LocalService
41+
FileMask: 'advanced_ip_scanner_Aliases.bin'
42+
43+
-
44+
Name: Advanced IP Scanner Aliases - NetworkService User Folder
45+
Category: Apps
46+
Path: C:\Windows\ServiceProfiles\NetworkService
47+
FileMask: 'advanced_ip_scanner_Aliases.bin'
48+
49+
-
50+
Name: Advanced IP Scanner Comments - User Folder
51+
Category: Apps
52+
Path: C:\Users\%user%
1853
FileMask: 'advanced_ip_scanner_Comments.bin'
19-
Recursive: true
2054

2155
-
22-
Name: Advanced IP Scanner MAC
56+
Name: Advanced IP Scanner Comments - User Temp Folder
2357
Category: Apps
24-
Path: C:\
58+
Path: C:\Users\%user%\AppData\Local\Temp\Advanced IP Scanner 2
59+
FileMask: 'advanced_ip_scanner_Comments.bin'
60+
61+
-
62+
Name: Advanced IP Scanner Comments - Windows Temp Folder
63+
Category: Apps
64+
Path: C:\Windows\Temp\Advanced IP Scanner 2
65+
FileMask: 'advanced_ip_scanner_Comments.bin'
66+
67+
-
68+
Name: Advanced IP Scanner Comments - SYSTEM SysWOW64 User Folder
69+
Category: Apps
70+
Path: C:\Windows\SysWOW64\config\systemprofile
71+
FileMask: 'advanced_ip_scanner_Comments.bin'
72+
73+
-
74+
Name: Advanced IP Scanner Comments - SYSTEM User Folder
75+
Category: Apps
76+
Path: C:\Windows\System32\config\systemprofile
77+
FileMask: 'advanced_ip_scanner_Comments.bin'
78+
79+
-
80+
Name: Advanced IP Scanner Comments - LocalService User Folder
81+
Category: Apps
82+
Path: C:\Windows\ServiceProfiles\LocalService
83+
FileMask: 'advanced_ip_scanner_Comments.bin'
84+
85+
-
86+
Name: Advanced IP Scanner Comments - NetworkService User Folder
87+
Category: Apps
88+
Path: C:\Windows\ServiceProfiles\NetworkService
89+
FileMask: 'advanced_ip_scanner_Comments.bin'
90+
91+
-
92+
Name: Advanced IP Scanner MAC - User Folder
93+
Category: Apps
94+
Path: C:\Users\%user%
95+
FileMask: 'advanced_ip_scanner_MAC.bin'
96+
97+
-
98+
Name: Advanced IP Scanner MAC - User Temp Folder
99+
Category: Apps
100+
Path: C:\Users\%user%\AppData\Local\Temp\Advanced IP Scanner 2
101+
FileMask: 'advanced_ip_scanner_MAC.bin'
102+
103+
-
104+
Name: Advanced IP Scanner MAC - Windows Temp Folder
105+
Category: Apps
106+
Path: C:\Windows\Temp\Advanced IP Scanner 2
107+
FileMask: 'advanced_ip_scanner_MAC.bin'
108+
109+
-
110+
Name: Advanced IP Scanner MAC - SYSTEM SysWOW64 User Folder
111+
Category: Apps
112+
Path: C:\Windows\SysWOW64\config\systemprofile
113+
FileMask: 'advanced_ip_scanner_MAC.bin'
114+
115+
-
116+
Name: Advanced IP Scanner MAC - SYSTEM User Folder
117+
Category: Apps
118+
Path: C:\Windows\System32\config\systemprofile
119+
FileMask: 'advanced_ip_scanner_MAC.bin'
120+
121+
-
122+
Name: Advanced IP Scanner MAC - LocalService User Folder
123+
Category: Apps
124+
Path: C:\Windows\ServiceProfiles\LocalService
125+
FileMask: 'advanced_ip_scanner_MAC.bin'
126+
127+
-
128+
Name: Advanced IP Scanner MAC - NetworkService User Folder
129+
Category: Apps
130+
Path: C:\Windows\ServiceProfiles\NetworkService
25131
FileMask: 'advanced_ip_scanner_MAC.bin'
132+
133+
-
134+
Name: Advanced IP Scanner Favorites - User Folder
135+
Category: Apps
136+
Path: C:\Users\%user%
137+
FileMask: 'advanced_ip_scanner_Favorites.bin'
138+
139+
-
140+
Name: Advanced IP Scanner Favorites - User Temp Folder
141+
Category: Apps
142+
Path: C:\Users\%user%\AppData\Local\Temp\Advanced IP Scanner 2
143+
FileMask: 'advanced_ip_scanner_Favorites.bin'
144+
145+
-
146+
Name: Advanced IP Scanner Favorites - Windows Temp Folder
147+
Category: Apps
148+
Path: C:\Windows\Temp\Advanced IP Scanner 2
149+
FileMask: 'advanced_ip_scanner_Favorites.bin'
150+
151+
-
152+
Name: Advanced IP Scanner Favorites - SYSTEM SysWOW64 User Folder
153+
Category: Apps
154+
Path: C:\Windows\SysWOW64\config\systemprofile
155+
FileMask: 'advanced_ip_scanner_Favorites.bin'
156+
157+
-
158+
Name: Advanced IP Scanner Favorites - SYSTEM User Folder
159+
Category: Apps
160+
Path: C:\Windows\System32\config\systemprofile
161+
FileMask: 'advanced_ip_scanner_Favorites.bin'
162+
163+
-
164+
Name: Advanced IP Scanner Favorites - LocalService User Folder
165+
Category: Apps
166+
Path: C:\Windows\ServiceProfiles\LocalService
167+
FileMask: 'advanced_ip_scanner_Favorites.bin'
168+
169+
-
170+
Name: Advanced IP Scanner Favorites - NetworkService User Folder
171+
Category: Apps
172+
Path: C:\Windows\ServiceProfiles\NetworkService
173+
FileMask: 'advanced_ip_scanner_Favorites.bin'
174+
175+
-
176+
Name: Advanced IP Scanner Favorites
177+
Category: Apps
178+
Path: C:\
179+
FileMask: 'advanced_ip_scanner_Favorites.bin'
26180
Recursive: true
27181

28182
# Documentation
29183
# Advanced IP Scanner is a scanning tool commonly leveraged by threat actors.
30-
# After closing the program it writes three files the most important of which is advanced_ip_scanner_MAC.bin which contains a list of IPs and System Names the Program Scanned.
184+
# After closing the program it writes three or four files the most important of which is advanced_ip_scanner_MAC.bin which contains a list of IPs and System Names the Program Scanned.
185+
# advanced_ip_scanner_Favorites.bin has been observed to behave differently to the other files. When run in portable mode it saves the .bin file beside the .exe rather than in a temp folder.
186+
# For performance reasons it is recommended to comment out the recursive Favorites rule with #s. On bigger disks with many files it could add hours on to the triage collection.
31187
# https://www.advanced-ip-scanner.com/
Lines changed: 166 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,31 +1,187 @@
11
Description: Advanced Port Scanner Artifacts
22
Author: Reece394
3-
Version: 1.0
3+
Version: 1.1
44
Id: 234332ea-77ca-4169-84ac-da28069fff84
55
RecreateDirectories: true
66
Targets:
77
-
8-
Name: Advanced Port Scanner Aliases
8+
Name: Advanced Port Scanner Aliases - User Folder
99
Category: Apps
10-
Path: C:\
10+
Path: C:\Users\%user%
1111
FileMask: 'advanced_port_scanner_Aliases.bin'
12-
Recursive: true
1312

1413
-
15-
Name: Advanced Port Scanner Comments
14+
Name: Advanced Port Scanner Aliases - User Temp Folder
1615
Category: Apps
17-
Path: C:\
16+
Path: C:\Users\%user%\AppData\Local\Temp\Advanced Port Scanner 2
17+
FileMask: 'advanced_port_scanner_Aliases.bin'
18+
19+
-
20+
Name: Advanced Port Scanner Aliases - Windows Temp Folder
21+
Category: Apps
22+
Path: C:\Windows\Temp\Advanced Port Scanner 2
23+
FileMask: 'advanced_port_scanner_Aliases.bin'
24+
25+
-
26+
Name: Advanced Port Scanner Aliases - SYSTEM SysWOW64 User Folder
27+
Category: Apps
28+
Path: C:\Windows\SysWOW64\config\systemprofile
29+
FileMask: 'advanced_port_scanner_Aliases.bin'
30+
31+
-
32+
Name: Advanced Port Scanner Aliases - SYSTEM User Folder
33+
Category: Apps
34+
Path: C:\Windows\System32\config\systemprofile
35+
FileMask: 'advanced_port_scanner_Aliases.bin'
36+
37+
-
38+
Name: Advanced Port Scanner Aliases - LocalService User Folder
39+
Category: Apps
40+
Path: C:\Windows\ServiceProfiles\LocalService
41+
FileMask: 'advanced_port_scanner_Aliases.bin'
42+
43+
-
44+
Name: Advanced Port Scanner Aliases - NetworkService User Folder
45+
Category: Apps
46+
Path: C:\Windows\ServiceProfiles\NetworkService
47+
FileMask: 'advanced_port_scanner_Aliases.bin'
48+
49+
-
50+
Name: Advanced Port Scanner Comments - User Folder
51+
Category: Apps
52+
Path: C:\Users\%user%
1853
FileMask: 'advanced_port_scanner_Comments.bin'
19-
Recursive: true
2054

2155
-
22-
Name: Advanced Port Scanner MAC
56+
Name: Advanced Port Scanner Comments - User Temp Folder
2357
Category: Apps
24-
Path: C:\
58+
Path: C:\Users\%user%\AppData\Local\Temp\Advanced Port Scanner 2
59+
FileMask: 'advanced_port_scanner_Comments.bin'
60+
61+
-
62+
Name: Advanced Port Scanner Comments - Windows Temp Folder
63+
Category: Apps
64+
Path: C:\Windows\Temp\Advanced Port Scanner 2
65+
FileMask: 'advanced_port_scanner_Comments.bin'
66+
67+
-
68+
Name: Advanced Port Scanner Comments - SYSTEM SysWOW64 User Folder
69+
Category: Apps
70+
Path: C:\Windows\SysWOW64\config\systemprofile
71+
FileMask: 'advanced_port_scanner_Comments.bin'
72+
73+
-
74+
Name: Advanced Port Scanner Comments - SYSTEM User Folder
75+
Category: Apps
76+
Path: C:\Windows\System32\config\systemprofile
77+
FileMask: 'advanced_port_scanner_Comments.bin'
78+
79+
-
80+
Name: Advanced Port Scanner Comments - LocalService User Folder
81+
Category: Apps
82+
Path: C:\Windows\ServiceProfiles\LocalService
83+
FileMask: 'advanced_port_scanner_Comments.bin'
84+
85+
-
86+
Name: Advanced Port Scanner Comments - NetworkService User Folder
87+
Category: Apps
88+
Path: C:\Windows\ServiceProfiles\NetworkService
89+
FileMask: 'advanced_port_scanner_Comments.bin'
90+
91+
-
92+
Name: Advanced Port Scanner MAC - User Folder
93+
Category: Apps
94+
Path: C:\Users\%user%
95+
FileMask: 'advanced_port_scanner_MAC.bin'
96+
97+
-
98+
Name: Advanced Port Scanner MAC - User Temp Folder
99+
Category: Apps
100+
Path: C:\Users\%user%\AppData\Local\Temp\Advanced Port Scanner 2
101+
FileMask: 'advanced_port_scanner_MAC.bin'
102+
103+
-
104+
Name: Advanced Port Scanner MAC - Windows Temp Folder
105+
Category: Apps
106+
Path: C:\Windows\Temp\Advanced Port Scanner 2
107+
FileMask: 'advanced_port_scanner_MAC.bin'
108+
109+
-
110+
Name: Advanced Port Scanner MAC - SYSTEM SysWOW64 User Folder
111+
Category: Apps
112+
Path: C:\Windows\SysWOW64\config\systemprofile
113+
FileMask: 'advanced_port_scanner_MAC.bin'
114+
115+
-
116+
Name: Advanced Port Scanner MAC - SYSTEM User Folder
117+
Category: Apps
118+
Path: C:\Windows\System32\config\systemprofile
119+
FileMask: 'advanced_port_scanner_MAC.bin'
120+
121+
-
122+
Name: Advanced Port Scanner MAC - LocalService User Folder
123+
Category: Apps
124+
Path: C:\Windows\ServiceProfiles\LocalService
125+
FileMask: 'advanced_port_scanner_MAC.bin'
126+
127+
-
128+
Name: Advanced Port Scanner MAC - NetworkService User Folder
129+
Category: Apps
130+
Path: C:\Windows\ServiceProfiles\NetworkService
25131
FileMask: 'advanced_port_scanner_MAC.bin'
132+
133+
-
134+
Name: Advanced Port Scanner Favorites - User Folder
135+
Category: Apps
136+
Path: C:\Users\%user%
137+
FileMask: 'advanced_port_scanner_Favorites.bin'
138+
139+
-
140+
Name: Advanced Port Scanner Favorites - User Temp Folder
141+
Category: Apps
142+
Path: C:\Users\%user%\AppData\Local\Temp\Advanced Port Scanner 2
143+
FileMask: 'advanced_port_scanner_Favorites.bin'
144+
145+
-
146+
Name: Advanced Port Scanner Favorites - Windows Temp Folder
147+
Category: Apps
148+
Path: C:\Windows\Temp\Advanced Port Scanner 2
149+
FileMask: 'advanced_port_scanner_Favorites.bin'
150+
151+
-
152+
Name: Advanced Port Scanner Favorites - SYSTEM SysWOW64 User Folder
153+
Category: Apps
154+
Path: C:\Windows\SysWOW64\config\systemprofile
155+
FileMask: 'advanced_port_scanner_Favorites.bin'
156+
157+
-
158+
Name: Advanced Port Scanner Favorites - SYSTEM User Folder
159+
Category: Apps
160+
Path: C:\Windows\System32\config\systemprofile
161+
FileMask: 'advanced_port_scanner_Favorites.bin'
162+
163+
-
164+
Name: Advanced Port Scanner Favorites - LocalService User Folder
165+
Category: Apps
166+
Path: C:\Windows\ServiceProfiles\LocalService
167+
FileMask: 'advanced_port_scanner_Favorites.bin'
168+
169+
-
170+
Name: Advanced Port Scanner Favorites - NetworkService User Folder
171+
Category: Apps
172+
Path: C:\Windows\ServiceProfiles\NetworkService
173+
FileMask: 'advanced_port_scanner_Favorites.bin'
174+
175+
-
176+
Name: Advanced Port Scanner Favorites
177+
Category: Apps
178+
Path: C:\
179+
FileMask: 'advanced_port_scanner_Favorites.bin'
26180
Recursive: true
27181

28182
# Documentation
29183
# Advanced Port Scanner is a scanning tool commonly leveraged by threat actors.
30-
# After closing the program it writes three files the most important of which is advanced_port_scanner_MAC.bin which contains a list of IPs and System Names the Program Scanned.
184+
# After closing the program it writes three or four files the most important of which is advanced_port_scanner_MAC.bin which contains a list of IPs and System Names the Program Scanned.
185+
# advanced_port_scanner_Favorites.bin has been observed to behave differently to the other files. When run in portable mode it saves the .bin file beside the .exe rather than in a temp folder.
186+
# For performance reasons it is recommended to comment out the recursive Favorites rule with #s. On bigger disks with many files it could add hours on to the triage collection.
31187
# https://www.advanced-port-scanner.com/

0 commit comments

Comments
 (0)