← Back to SOC feed Coverage →

PUA - Advanced IP/Port Scanner Update Check

sigma MEDIUM SigmaHQ
T1590
imWebSession
This rule was pulled from an open-source repository and enriched with AI. Validate in a test environment before deploying to production.
View original rule at SigmaHQ →
Retrieved: 2026-03-25T02:50:08Z · Confidence: medium

Hunt Hypothesis

Adversaries may use Advanced IP/Port Scanner utilities to perform update checks that mask lateral movement or reconnaissance activities. SOC teams should proactively hunt for this behavior in Azure Sentinel to identify potential network scanning and compromise indicators early.

Detection Rule

Sigma (Original)

title: PUA - Advanced IP/Port Scanner Update Check
id: 1a9bb21a-1bb5-42d7-aa05-3219c7c8f47d
status: test
description: Detect the update check performed by Advanced IP/Port Scanner utilities.
references:
    - https://www.advanced-ip-scanner.com/
    - https://www.advanced-port-scanner.com/
author: Axel Olsson
date: 2022-08-14
modified: 2024-02-15
tags:
    - attack.discovery
    - attack.reconnaissance
    - attack.t1590
logsource:
    category: proxy
detection:
    selection:
      # Example request: http://www.advanced-port-scanner.com/checkupdate.php?lng=en&ver=2-5-3680&beta=n&type=upd&rmode=p&product=aps
      # Example request2: http://www.advanced-ip-scanner.com/checkupdate.php?lng=en&ver=2-5-3499&beta=n&type=upd&rmode=p&product=aips
        c-uri|contains: '/checkupdate.php'
        c-uri-query|contains|all:
            - 'lng='
            - 'ver='
            - 'beta='
            - 'type='
            - 'rmode='
            - 'product='
    condition: selection
falsepositives:
    - Expected if you legitimately use the Advanced IP or Port Scanner utilities in your environement.
level: medium

KQL (Azure Sentinel)

imWebSession
| where Url contains "/checkupdate.php" and (Url contains "lng=" and Url contains "ver=" and Url contains "beta=" and Url contains "type=" and Url contains "rmode=" and Url contains "product=")

False Positive Guidance

MITRE ATT&CK Context

Original source: https://github.com/SigmaHQ/sigma/blob/master/rules/web/proxy_generic/proxy_pua_advanced_ip_scanner_update_check.yml