Akira - SoftPerfect Network Scanner and Invoke-ShareFinder Enumeration
This rule detects various reconnaissance techniques commonly used to identify network resources, including the execution of SoftPerfect Network Scanner (or renamed binaries), the creation of 'delete.me' files used by SoftPerfect to probe share permissions, the usage of the 'Invoke-ShareFinder' PowerShell script, and the enumeration of network shares using 'net.exe' initiated from PowerShell.
Cortex XDR

