APT36 Local Network Recon via arp/nbtstat/net view/ping Sweeps
Detects host-based network reconnaissance behaviors commonly associated with the threat group APT36 (Transparent Tribe). The rule identifies the execution of various built-in Windows network discovery commands including arp, nbtstat, net view/share/session, and automated ping sweeps or PowerShell-based subnet enumeration scripts, which are used to map reachable hosts and network shares.
YARA-L

