Vulnerability Scanner Activity Detection
This rule detects the execution of processes with command lines containing keywords associated with common vulnerability scanners such as 'scanner', 'nessus', or 'qualys'. It aggregates these events by computer and account over one-hour intervals to identify potential vulnerability scanning activity within the environment.
Microsoft Sentinel (KQL)

